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Harness Heat & 

Power Consumption 

Get Your Data Center Out Of The Hot Seat In 2010 



by Christian Perry 
• ■ • 

Data centers aren't the only things chugging along into the new year, as 
heat is anticipated to have yet another successful year of delivering 
headaches to infrastructure managers around the globe. However, by under- 
taking a project in 2010 that can help to keep temperatures and power con 
sumption under control, data centers can force heat to look elsewhere to continue 
its productive run. 

An easy approach to controlling rising temperatures is simply to throw more cooling 
at the heat, but then the data center faces increased power consumption costs. The chal- 
lenge, then, is to achieve acceptable temperature levels while keeping an active eye on 
green IT measures. This process is by no means simple, but it's also not necessarily 
expensive nor out of the expertise realm of even small data centers. 

Hit The Heat 

Analysis is key to understanding the temperature range that 
your data center should achieve both now and for the 
next several years, says Rudy Rangel, sales manager 
Go to Page 6 




2010 



Key Points 



Targeting tennperature-related problems 
requires close analysis of not only your 
current environment but also your existing 
systenns and their dependencies on other 
parts of the data center. 
By working to cut power consumption, you 
can help to control temperatures while 
saving on perpetually rising energy costs. 
Depending on the scope of the project, 
costs can range from a few hundred dollars 
to tens of thousands, but keeping an eye 
toward reducing energy consumption can 
help to offset initial investments. 




Data Classification 

Make Sure Your SME Is Employing The Right Strategy 



by Elizabeth Millard 

Increasingly, backup and security plans 
focus on different tiers of data because 
not all information within a corporate 
system is mission-critical. But how can 
an IT manager classify data assets to 
make sure they're being shuttled to 
the right storage areas and are secured 



properly? Here are some insights on get- 
ting started and implementing a solid 
classification strategy. 

Use l\/letadata 

Data about data — called metadata — can 
be used to focus and accelerate the data 
classification process, notes Raphael Reich, 
senior director of marketing at Varonis 



Systems (www.varonis.com), a firm spe- 
cializing in unstructured data governance. 

Common examples might include file 
sizes, types, and locations. Also helpful is 
access permissions data, which helps deter- 
mine what data a specific user or group can 
or cannot access. A benefit to gathering 
that info might be a glimpse into what data 
Go to Page 6 
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straightfonward. But with virtualized servers, software 
licensing has become much more complex page 43 

■ There are several steps IT staff can take to cut the 
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News 



I Online Holiday 
Shopping Rebounds . . . 

It's good news for the 
economy as a whole as 
well as for a host of IT 
vendors: Shopping on the 
Web made a year-over- 
year comeback during the 
2009 holiday season. 
Research firm comScore 
reports that consumer e- 
commerce climbed 5% over 
2008 to about $27.1 billion 
for the Nov. 1 to Dec. 24 
timeframe. Growth was about 
3.5% year-over-year for the Black 
Friday-to-Christmas Eve period. Con- 
sumer electronics shone as a category with 
more than 20% growth. However, the amount 
spent per shopper declined a little as compared 
to the 2008 holiday shopping season. 

I ... & Online Shoppers Are Becoming 
More Satisfied 

Satisfaction with e-commerce sites was up 7% 
during the 2009 holiday season, with a total 
score of 79 out of 100, according to the latest 
data from ForeSee Results' E-Retail Satisfac- 
tion Index. Amazon took the top ranking in 
terms of customer satisfaction, scoring 87 out of 
100. Apple led in terms of computer and elec- 
tronics companies with a score of 82, up four 
points from 2008. Dell scored 79 (up five points 
from 2008), while HP scored 78 (up two points). 

I Nuance Acquires SpinVox 

Nuance Communications announced that it has 
acquired international voice-to-text provider 
SpinVox. The $102.5 million deal consisted of 
a cash payout of $66 million along with a $36.5 
million stock purchase at a little less than $16 




per share. The American speech 
recognition platform provider 
expects that the addition of 
UK-based SpinVox will beef 
up its international presence 
and technology portfolio. The 
deal will also improve the quali- 
ty of service the company pro- 
vides to telecom carriers in the 
area of voicemail-to-messaging 
automation and management. 
Nuance says. 

I "Soupnazi" Hacl(er 
Makes Plea Agreement 

Accused hacker Albert Gonzalez pled guilty 
late last month to two counts of conspiring to 
gain unauthorized access to the payment card 
networks of several U.S. retailers and financial 
institutions to steal information on tens of mil- 
lions of credit card and debit card accounts. 
Under the plea agreement, Gonzalez, a Miami 
resident who went by the names "soupnazi" and 
"segvec," faces a 17- to 25-year prison sen- 
tence. In a statement, the U.S. Department of 
Justice said, "The case is one of the largest data 
breaches ever investigated and prosecuted in 
the United States." Gonzalez also faces sen- 
tencing related to charges filed in Massachu- 
setts and New York, although the sentencing will 
run concurrently per his plea agreement. Among 
Gonzalez's targets were payment card networks 
operated by 7-Eleven, Hannaford Brothers, and 
Heartland Payment Systems. He also tested 
and stored malware aimed at attacking networks 
and stealing data involving 250 financial organi- 
zations on several networks. 

I Google Loses Claim To Groovle.com 
Domain Name 

Google's attempt to block Canadian Web site 
operator 207 Media from using the Groovle.com 



WATCH THE This 

STOCKS - 



3 information provides a quick glimpse of current and historical stock 
;es and trends for 14 major companies in the technology market. 



Company 


Symbol 


Year Ago 


Dec. 22 $ 


Jan. 7 $ 


previous issue 


AMD 


AMD 


$2.69 


$9.43 


$9.47 


▲ 0.42% 


OA 


CA 


$18.42 


$22.60 


$22.87 


▲ 1.19% 


Cisco Systems 


CSCO 


$16.70 


$23.75 


$24.53 


A 3.28% 


Dell 


DELL 


$11.12 


$14.11 


$14.72 


▲ 4.32% 


Google 


GOOG 


$315.07 


$601.12 


$594.10 


T 1.17% 


HP 


HPQ 


$37.49 


$52.46 


$52.20 


T 0.5% 


IBM 


IBM 


$84.70 


$129.93 


$129.55 


T 0.29% 


Intel 


INTC 


$14.15 


$20.04 


$20.60 


▲ 2.79% 


McAfee 


MFE 


$31.38 


$39.77 


$40.42 


▲ 1 .63% 


Microsoft 


MSFT 


$19.52 


$30.82 


$30.45 


T 1 .2% 


Oracle 


ORCL 


$17.36 


$24.46 


$24.38 


T 0.33% 


Red Hat Software 


RHT 


$15.46 


$29.87 


$30.39 


A 1 .74% 


Sun Microsystems 


JAVA 


$4.66 


$9.33 


$9.40 


▲ 0.75% 


Symantec 


SYMC 


$13.60 


$17.71 


$18.32 


▲ 3.44% 



NOTE: This information is meant for reference oniy and sliouid not be used as a basis for buy/seil decisions. 



domain name was rejected late last month by 
the three-person NAF (National Arbitration 
Forum) panel. In its November-filed complaint, 
Google argued that Groovle.com was "nearly 
identical or confusingly similar" to the Google 
trademark, but the NAF panel ruled that the 
name was sufficiently different. Google also 
argued that Groovle.com's layout of the search 
box and other items are highly similar to the lay- 
out of Google's search home page. Jacob Fuller 
and Ryan Fitzgibbon created the Google-pow- 
ered Groovle.com in 2007. The site provides 
users starting pages they can customize with 
personal photos and then conduct Web search- 
es from. In its ruling, the NAF stated that the dis- 
similar letters in Groovle.com's domain name 
are sufficiently different to make it distinguish- 
able from Google's mark "because the domain 
name creates an entirely new word and conveys 
an entirely singular meaning from the mark." 

I Study Outlines Dangers 
OfTexting While Driving 

Another study has been released that shows 
texting while driving isn't safe. In fact, accord- 
ing to the study, which was conducted by re- 
searchers at the University of Utah, a texter is 
six times more likely to be involved in an acci- 
dent than someone who is undistracted. The 
study involved 20 men and 20 women, ages 
19 to 23, texting while operating a driving simu- 
lator. Each participant had texting experience 
and had been driving for less than five years. 
Participants suffered delayed reaction times, 
followed other drivers too closely, and were 
slower to apply their brakes. Overall, their reac- 
tion time was diminished by 30% compared to 
9% for someone talking on a cell phone. 

I Apple Acquires UobWe Ad Company 
Quattro Wireless 

Apple has acquired mobile advertising compa- 
ny Quattro Wireless for a reported $275 mil- 
lion. Waltham, Mass., -based Quattro Wireless 
offers Q Elevation, its mobile-specific targeting 
platform for delivering audience-appropriate 
mobile ads, and its customers include compa- 
nies such as Microsoft, Procter & Gamble, and 
Visa. The acquisition brings Apple into increas- 
ing competition with Google, which acquired 
AdMob, another mobile advertising firm and 
Quattro competitor, in November at a price 
tag of $750 million, although U.S. antitrust 
regulators are currently reviewing 
the deal. Also heightening 
the competition 
between Google 
and Apple is 
Google's an- 
nouncement 
of the Nexus 
Qne mobile 
phone, which 
could rival 
Apple's iPhone 
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I Advertising Coalition Finds 
Ad Networl(s Mostly In Compliance 

The Network Advertising Initiative, a group 
of more tlian 35 online marketing companies, 
created a code of conduct in December 2008 
related to the transparency, notice, choice, col- 
lection, and use of personally identifiable infor- 
mation in online advertising. The code has 
been in effect for about a year, and the NAI 
says that the companies it monitors "met their 
compliance obligations with respect to the 
great majority of the requirements of the NAI 
Code." Charles Curran, the NAI's executive 
director, says the review shows that NAI mem- 
bers "take consumer transparency and choice 
for online behavioral advertising very serious- 
ly." Although the NAI says member companies 
showed "no compliance deficiencies" when it 
came to the new code, several member com- 
panies are working to improve in certain areas, 
including the ways in which they disclose data 
retention periods. 

I Windows 7 Influencing IT Spending 

A report from ChangeWave found 
that nearly one in five corpo- 
rate IT buyers say that 
Windows 7 is bumping up 
the pace of their com- 
puter upgrade cycles. 
Of the 1 ,700 IT profes- 
sionals surveyed, 93% 
said that their compa- 
nies are satisfied with 
Win7. Additionally, 10% said 
that their enterprises have 
already purchased PCs with Win7 installed. 
When asked if their companies plan on spend- 
ing more on Microsoft products, 26% said they 
will in the next quarter, which is up from 16% in 
August and 1 0% last February. 

I Smart Grid Spending On The Rise 

In a recent report. Pike Research says it 
expects government and utility companies to 
spend about $200 billion worldwide from 
2008 to 2015 on smart grid technology, which 
is the digitized management of electrical 
power in order to help both consumers and 
companies use energy more efficiently. Pike 
expects that 84% of the spending will be on 
the technologies that automate the grid and 
balance power generation supply and 
demand. Another 14% of the funds will go 
into smart metering technologies that monitor 
and analyze the use of electricity, gas, and 
water. Pike predicts the remaining 2% will be 
invested in technology that provides energy 
to electric cars. 





I Oracle Buys Silver Creek Systems 

California-based software maker Oracle has 
acquired Silver Creek Systems in an attempt 
to improve its information management sys- 
tems with the addition of data quality manage- 
ment capabilities. Silver Creek Systems' 
DataLens software will help Oracle simplify 
and standardize product descriptions. The 
purchase will ensure improved management 
of various Oracle software programs, includ- 
ing supply chain management, customer rela- 
tionship management, and product lifecycle 
management. The company says future 
spending on the research and development of 
this software will increase. Financial details of 
the deal were not disclosed; however, Oracle 



stock increased 32 cents per share (1.3%) the 
day of the purchase. 

I Office 2010 Pricing 

Microsoft has released pricing details for 
Office 2010. The four versions include Office 
2010 Home And Student, Home And Busi- 
ness, Professional, and an academic version 
of Office Professional, which are expected to 
be available later this year for $1 49, $279, 
$499, and $99, respectively. Office 2010 
Home And Student includes the most popular 
applications: Word, Excel, PowerPoint, and 
OneNote. Office Home And Business includes 
the same applications with the addition of Out- 
look. Both the academic and nonacademic 
versions of Office Professional feature Pub- 
lisher and Access. Microsoft is also releas- 
ing Office 2010 Product Key Cards for each 
version save Office Professional Academic 
that forego the boxed software in favor of a 
product key, which the customer can use 
to download and activate the software on 
one PC. Users can install all three non- 
academic versions on up to two PCs, but 
Office Professional Academic, available 
through authorized academic resellers only, 
in-cludes a license that lets users install 
the software on up to three PCs. 
Product Key Card pricing for Office 
Home And Student, Home And 
Business, and Office Professional 
will be $119, $199, and $349, 
respectively. 

I Forrester Studies 
The State Of Smartphones 

Forrester Research recently released its U.S. 
Omnibus Survey, which shows that about 
17% of mobile subscribers now own smart- 
phones based on the iPhone OS, the 
BlackBerry OS, Windows Mobile, PalmOS, 
WebOS, Sym-bian, or Linux (Android). That's 
compared to just 1 1 % toward the end of 2008 
and 7% at the end of 2007. In 2009, RIM's 
BlackBerry maintained the highest market 
share of all smartphones, largely due to, 
according to Forrester, its price, availability, 
and full QWERTY keyboard. Forrester distin- 
guishes quick messaging devices from smart- 
phones, due to their lack of a standard smart- 
phone OS. Forrester reports that 15% of adult 
subscribers owned one of these phones in 
2009, compared to 9% in 2008. Forrester 
believes that 201 will be an even bigger year 
for smartphones than 2009 was. 

I EMC To Acquire Archer Technologies 

storage and security manufacturer EMC 
recently announced that it plans to buy Archer 
Technologies, a supplier of enterprise gover- 
nance, risk, and compliance solutions that has 
more than 6 million licensed users. Although 
the financial details were not disclosed, EMC 
says Archer will operate as part of EMC's RSA 
Security Division and remain in its original loca- 
tion of Overland Park, Kan. EMC expects the 
acquisition of Archer will benefit EMC's recently 
acquired lonix unit. 

I Chrome Passes Safari 
In Browser Usage 

statistics published 
by analytics firm Net 
Applications show 
that Google's Chrome 
browser has surpassed 
Apple's Safari in number 
of users. The number of 
users browsing with Chrome went 
from 3.9% to 4.6% in December, while Safari 
ranked at only 4.5%. The statistics are based 
on 160 million monthly visitors that browse to 
a network of sites that use Net Applications' 
services. Coming in ahead of both and all 
other included browsers was Microsoft's Inter- 
net Explorer, with 62.69% of users. Coming 
in second was Mozilla's Firefox, with 24.61% 
of users. 



I Broadcom Settles 
Shareholder Lawsuit 

Broadcom will divvy out $160.5 million in a set- 
tlement regarding the company's backdating 
practices. As per the settlement, any claims 
against Broadcom officers and directors are to 
be dismissed, and the company will take a 
fourth-quarter charge. The final deal will be the 
second largest up-front cash settlement in a 
suit against a company accused of stock option 
backdating. The lawsuit was filed by sharehold- 
ers who purchased or obtained Broadcom 
stock between July 21, 2005, and July 13, 
2006. Broadcom had to ultimately restate $2.2 
billion in earnings for a four-year period due to 
the backdating; however, the com- 
pany denies any wrongdoing in 
the case. 





I Ethernet 

Services See 

Boom In North America 

In contrast to the economic downturn, carrier 
Ethernet sen/ices are seeing double-digit rate 
increases. According to a recent report from 
Heavy Reading, a market research organiza- 
tion, Ethernet connectivity services are increas- 
ingly being incorporated into vertical industries. 
Based on input by 20 carriers, the report also 
indicated that retail and wholesale Ethernet 
services have survived the poor economy, 
even as traditional frame relay, ATM, and 
TDM private line services continue to decline. 
Other key results reveal that the Ethernet ser- 
vice market is now a mainstream revenue 
source, companies are embracing Ethernet 
beyond adoption and performance reasons, 
and service providers are penetrating the mar- 
ket at both the connectivity level and the appli- 
cation level. 

I HP Exec Heads To Intermec 

Jim McDonnell is leaving his executive position 
at HP for Intermec, which produces machines 
for automated identification and data capture. 
McDonnell has been named a senior vice presi- 
dent of global sales at Intermec and has vacat- 
ed his post as the vice president of global sales 
in HP's Enterprise Storage, Servers, and Net- 
working Group after working at HP for 26 years. 
Intermec earned $35.7 million in 2008, as com- 
pared to the $10.5 billion HP profited, but 
Intermec has recently snagged other exec- 
utives from large companies. 

I IDC Survey Finds Concerns 
Among IT 

A recent survey conducted by IDC shows 
that security was the biggest concern in 2009 
for IT cloud services; availability and perfor- 
mance were listed as the second and third con- 
cerns. The survey, which questioned 263 IT 
personnel, also found that there was trepida- 
tion over whether a cloud model would be more 
expensive than a noncloud model. Although IT 
personnel have been slightly uneasy about the 
switch because of these challenges, the IDC 
survey found that many adopters of cloud mod- 
els have made the leap for economic gain. 
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Are you looking to learn more about data center 
or IT topics? Network with some of your peers? 

Consider joining a group of data center 
professionals. If you have an event you'd like 
listed, please send an email to 
feedback@processor.com. 



- JANUARY - 

ISSA Upstate South Carolina 
Jan. 15 
NuVox 

301 N. Main St., Suite 5000 
Greensville, S.C. 
www.upstate-issa.org 



Exchange Server 2010 First Look & Hands on Lab 
Jan. 18, 8 a.m. to 4 p.m. 
Max Technical Training 
4900 Parkway Drive, Suite 160 
Mason, Ohio 
www.maxtrain.com 



AITP Southwest Missouri 
Jan. 19 
Springfield, Mo. 
aitpspringfield.org 



ISSA St. Louis Chapter 
Jan. 19 
St. Louis, Mo. 
stl.issa.org 



Oklahoma City AITP Chapter 
Jan. 19 
Oklahoma City, Okla. 
www.aitp.org/organization/chapters 
/chapterhome.jsp?chapter=40 



AITP Northeastern Wisconsin Chapter 
Jan. 20, 4:15 p.m. 
Holiday Inn Select 
150 S. Nicolet Road 
Appleton, Wis. 
new.aitp.org 



AITP Atlanta 
Jan. 21,5:30 p.m. 
Crowne Plaza Atlanta Perimeter NW 
6345 Powers Ferry Road NW 
Atlanta, Ga. 
www.aitpatlanta.org 



San Diego SQL Server User Group 
Jan. 21 
San Diego, Calif. 
www.sdsqlug.org 

ISSA Des Moines 
Jan. 25 
3920 SW Camden Circle 

Ankeny, Iowa 
www.issa-desmoines.org 



AITP Akron 

Jan. 26 
Akron, Ohio 
www.akron-aitp.org 



ISSA Inland Empire 
Jan. 26 
ie.issa.org 



ISSA Baltimore 
Jan. 27, 4:30 p.m. 
Sparta Inc. 
7110 Samuel Morse Drive, Suite 200 
Columbia, Md. 
www.issa-balt.org 



AITP California Southland 

Jan. 27 
www.aitpcalsouthland.org 

- FEBRUARY - 

Windows Server 2008-What's New Hands on Lab 
Feb. 1-2, 8 a.m. to 4 p.m. 
Max Technical Training 
4900 Parkway Drive, Suite 160 
Mason, Ohio 
www.maxtrain.com 



Green Data Center Conference 
Feb. 2 

University Of California San Diego 
San Diego Super Computer Center 
10100 Hopkins Drive 
San Diego, Calif. 
greendatacenterconference.com 



AFCOM St. Louis "Gateway" Chapter 
Feb. 9 

Schneider Electric Technology Center 
807 Corporate Centre Drive 
O'Fallon, Mo. 
www.afcom.com/afcomnew/stlouls.html 



For more Upcoming IT Events, see page 8. 
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PRODUCT RELEASES 



The Processor Product Releases section 
includes brief overviews of data center products. 

All products listed have been released recently, so use this section to get 
up-to-date with what's new on the market and to find products you need. 



Clients 



■ Oracle SQL Developer 2.1 

Oracle announced version 2.1 of its SQL 
Developer. The free tool offers PL/SQL 
unit testing; data modeling viewer; and 
expanded database migration support, 
including Teradata and IBM DB2 UDB for 



Linux, Unix, and Windows. In addition, 
version 2.1 includes a background task 
capability that enables users to run time- 
consuming tasks using SQL in the back- 
ground while completing other tasks with 
the tool. Version 2.1 also uses enhanced 
data grids that offer dynamic searching, fil- 
tering, and highlighting. 



Networking & VPN 



■ Advanced Systems Concepts ActiveBatch 
V7 Service Pack 2 

Advanced Systems Concepts released 
ActiveBatch V7 Service Pack 2, which 
incorporates a series of new extensions and 
add-ins supporting Oracle jobs, SAP, and 
VMware platforms. Additionally, V7 Service 
Pack 2 expands ActiveBatch' s capabilities 
for the Microsoft System Center Operations 
Manager Management Pack. ActiveBatch 
can automate and centrally manage jobs 
and workflows across multiple and disparate 
operating systems, applications, and environ- 
ments. It offers an event-based architecture 
and a jobs library containing a list of "pro- 
duction-ready" job steps. ActiveBatch V7's 
Service Pack 2 further extends the sched- 
uler's interaction with leading enterprise 
applications and network elements. For 
example, it features an expansion in the num- 
ber and type of Oracle job steps, such as Get 
Job Status, Start Job, and Synchronize Job. 

■ Quest Software vWorkSpace 7.0 

Quest Software released the latest version 
of its vWorkspace desktop virtualization 
software, which now not only supports the 
VMware platform but also VMware Linked 
Clones, which reduces shared storage disk 
space requirements. The update also in- 
cludes enhancements that improve the end- 
user experience and expanded desktop plat- 
form choices, including new support for 
Windows 7, Windows 2008 and 2008 R2, 
Windows Vista, System Center Virtual 
Machine Manager 2008 R2, and Parallels 
Virtuozzo Containers. The company says 
the latest version also drives down costs and 
reduces the impact on backend resources. 
Additionally, it provides increased speed for 
flash media embedded in Internet Explorer. 

■ VISI ReliaCloud 

VISI launched a public beta of its Relia- 
Cloud service, which the company says is 
designed so that customers don't need to 
rearchitect their solutions to work reliably 
in the cloud. The service is ideally suited 
for IT managers in established, small to 
midsized organizations as well as startup 
organizations that want to take advantage 
of the cloud's economic benefits. Relia- 
Cloud is a set of secure cloud computing 
services — the first two are Cloud Servers 
and, coming soon. Cloud Storage. Relia- 
Cloud Servers offer computing environ- 
ments that you can provision 24 hours a 
day, with full administrator access. You 



can scale servers programmatically via an 
API over a Web management portal. 
Pricing starts at five cents per server hour. 



Physical Infrastructure 



■ Emerson Network Power Liebert Data 
Center Audit 

Emerson Network Power released the 
Liebert Data Center Audit, which is designed 
to identify, evaluate, and resolve cooling and 
power issues. The Liebert Data Center Audit 
covers data center virtualization, consolida- 
tion, and blade implantations and provides 
custom reports for data centers that are less 
than 2,500 square feet. The reports compare 
customer data with more than 50 industry 
benchmarks, including power, cooling, racks 
and cabling, and monitoring. 



Security 



■ Black Box Network Services Intelli-Pass 

Black Box Network Services unveiled its 
two-factor Intelli-Pass biometric fingerprint 
ID system designed to secure rooms, 
offices, and areas within a building against 
unauthorized entry. The two Intelli-Pass 
models, SAC510NA and SAC510SA, fea- 
ture an antitamper design, separate reader 




and controller units, and a protected door 
opening mechanism to foil would-be intrud- 
ers. The Intelli-Pass system protects reader 
and controller communication via Black 
Box's proprietary encryption scheme. In 
order to gain entry to an Intelli-Pass-secured 
location, users must type a PIN and submit 
to a fingerprint scan. Other features include 
the ability to network the system, remote 
access, logs of everyone entering and leav- 
ing, and the ability to grant access to certain 
users at certain times of the day. 

■ Fortinet FortiGate-5140 

Fortinet announced an achievement in 
IPv6 performance. Based on the company's 
FortiASIC technologies, which accelerate 
security processing through its FortiGate- 
5000 series blades and other ADM modules, 
the FortiGate-5140 multithreat chassis-based 
system delivered 56Gbps of IPv6 through- 
put. The achievement was validated using 
IPv6 testing performed by BreakingPoint 
Elite. Fortinet supports IPv6 with its FortiOS 
4.0 firmware, which has been certified by 
the IPv6 Ready Logo Program. 

■ Solutionary & e-Cop New Security Services 

Solutionary and e-Cop announced an 
alliance that will combine security monitor- 
ing, management, and compliance services to 
provide a new platform for enterprises, the 
public sector, and government organizations. 
The suite will include log monitoring, device 
management, and full BOT (Build, Operate, 
and Transfer) SOC services. It will feature 
full, global cross-correlation views of log 
data, threat intelligence monitoring, and mul- 
tiple device monitoring. 

■ Sun Microsystems Cloud Security 

Sun Microsystems announced additional 
open-source cloud security capabilities as 



well as support for the CSA's (Cloud 
Security Alliance) "Guidance for Critical 
Areas of Focus in Cloud Computing - 
Version 2.1" document. Designed to deliver 
secure and easily manageable enterprise- 
grade cloud services, Sun's Cloud Security 
architecture uses the built-in security features 
in the Solaris OS. The new Cloud Security 
tools include OpenSolaris VPC Gateway, 
ISCs (Immutable Service Containers), 
Security Enhanced VMIs (Virtual Machine 
Images), and Cloud Safety Box. 



Servers 



■ HP Nonstop BladeCluster Express 1.2, 
Nonstop SOAP 4.0 & NonStop SQL 2.3 
Database 

HP announced several updates to its 
NonStop server platform. The NonStop 
BladeCluster Express 1.2 is designed to 
assist customers with widely distributed 
enterprise data center systems that consist 
of thousands of processors. Another updat- 
ed offering, NonStop SOAP 4.0, helps users 
gather Business Intelligence by gathering 




data from across the enterprise. NonStop 
SQL 2.3 database provides users with better 
overall performance and increased service 
levels through simplified software program- 
ming and improved application capacity. 
HP also offers its Integrity NonStop cus- 
tomers access to its business technology 
user community. Connect, which lets them 
interact, share knowledge, and exchange 
best practices with one another. 



Storage 



■ DataCore Software Virtual Disk Expansion 

DataCore Software expanded the size 
of its virtual disks from 2TB to IPB 
(petabyte) in response to market demands. 
The company says that performance-wise, 
the larger virtual disks benefit from 
DataCore Software's 1TB per node, 64-bit 
mega-caches, allowing for large storage 
and quickness. DataCore says the expan- 
sion meets two industry trends, including 
clients who want to group numerous disk 
drives that each top 1TB into RAID sets 
and applications that must update and ana- 
lyze large datasets that will exceed 2TB 
caps in the foreseeable future. Concerning 
RAID sets, DataCore says its storage vir- 
tualization nodes can control pools con- 
taining numerous RAID sets with each 
exceeding the previous 2TB maximum. 
DataCore customers with current mainte- 
nance contracts can receive the IPB en- 
hancement free. 

■ EMC Symmetrix V-Max 

EMC enhanced its Symmetrix V-Max 
storage array to include 8Gbps connectivity 
for both mainframe and open systems envi- 
ronments. EMC has also enhanced Virtual 
Provisioning for Symmetrix V-Max sys- 
tems, which now includes zero space recla- 
mation, thick-to-thin and thin-to-thick sup- 
port for EMC TimeFinder/Clone software, 
and automated rebalancing of Virtual 
Provisioning storage pools as additional 
capacity is added. Other features include 



high-capacity system configurations built 
around two and four engines and software 
compression for EMC SRDF (Symmetrix 
Remote Data Facility) traffic over both Fibre 
Channel and Gigabit Ethernet connections. 

■ iStoragePro 8-Bay Safari 2.5-inch JBODs 

iStoragePro introduced two 8-bay Safari 
2.5-inch JBOD storage units. The 
iTSPESA and iTSPMIS, which are de- 
signed specifically for the audio/video 
industry, are enclosed in aluminum and 
have quiet cooling fans. The two devices 
have 4TB of storage; offer miniSAS and 
eSATA interfaces; and support 2K, 4K, 
full resolution 10801 HD, 720p, HDV, SD, 
and VEX. Additionally, with a MiniSAS 
and SATA II port multiplier chipset, the 
two devices easily handle uncompressed 
HD video. Finally, each device includes a 
high-speed PCI Express RAID Card for 
tough RAID protection, including RAID 
Level 0, 1, 5, 6, or 10 (depending on the 
RAID Card). 

■ LaCie & Symwave 2Big USB 3.0 

LaCie, along with Symwave, announced 
what the companies call the industry's first 
dual hard disk RAID storage solution based 
on the new SuperSpeed USB 3.0 standard. 
The companies say the LaCie 2Big USB 
3.0 has reached the highest throughput ever 
achieved in a USB 3.0 external storage 
product. It comes with up to 4TB of storage 
with a potential burst read transfer rate of 
275MBps. The LaCie 2Big USB 3.0 is 
powered by Symwave' s USB 3.0 standard- 
compliant dual SATA and RAID bridge 
controller, supports RAID types and 1, 
and comes with backup software for PC 
and Mac users. 

■ MicroNet MaxNAS 4R & 8R 

MicroNet announced rackmount addi- 
tions to its MaxNAS line of storage units 
for SMEs. The MaxNAS 4R is a lU model 
that supports up to four 3.5-inch SATA 
drives, while the 2U MaxNAS 8R supports 




up to eight. The MaxNAS 4R and 8R appli- 
ances can be configured with 1TB or 2TB 
drives to deliver up to 16TB of storage. 
Stackable to up to 96TB, the units feature 
iSCSI targets; dual IGbps Ethernet ports 
with link aggregation; and redundant and 
hot-swappable drive bays, power supplies, 
and cooling fans. The appliances offer sup- 
port for RAID 0/1/5/6/10/JBOD and IP- 
based video surveillance applications. 
Pricing starts at $1,679. 
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CyberView™ 

Cats KVM access over IP from anywhere around the world 




• Cat6 cable from KVM port to server end up to 40 meters 

• Cat6 cable up to 300 meters to remote access server 

• 8 / 16 / 32-port available 

• IP-based remote access function available 

• Matrix KVM allows simultaneous users for efficient system management 




Gate IP KVM 8/16/32 port 



Matrix Cat6 IP KVM 16/32 port 



Full range KVM integration 



1U20" 
1600 X 1200 



lUDual Slide 17" 
LCD KVM Drawer 






1U 19" Widescreen 
1440x900 




1U 17"/ 19" 
LCD KVM Drawer 




Austin Hughes 

At Austin Hughes, we are committed to providing 
our customers with quality products and excellent services 



8U 19" Widescreen 
LCD Quad Display 




8U 22" Widescreen LCD 
1680 X 1050 





1 U 20" LCD Drawer 
1600 X 1200 



AUSTIN 



Quality Commitment 

We insist upon using quality components in our products such as the Samsung A++ class LCD 
panel, which has an extended product life of more than five years. With an average defect rate of less 
than 1% during our two-year free service warranty, we want to ensure our customers' complete satisfaction. 



Full Range Product Series 

In addition to our excellent services, we offer a full range of products such as LCD KVM drawers, LCD display panels, keyboard drawers 
and KVM switches to meet our customers' needs. 

.Plea se contact our distributors for product inquiries. ^^^^^^^^^^^^^^ 
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Harness Heat & 
Power Consumption 



Continued from Page 1 
for Rackmount Solutions (www. rack 
mountsolutions.net). He recommends 
using temperature monitors to visualize 
current temperatures and see how they 
fluctuate during the day and various sea- 
sons. From there, ask questions: Are there 
hot spots? Are the temperatures on nights 
and weekends set higher than during 
weekdays? Are you determining your 
ideal range based on typical server-room 
wisdom of 68 to 72 degrees Fahrenheit? 

Also, determine whether you are having 
equipment failure now or if you can safely 
boost temperatures. For example, Rangel 
notes that some manufacturers now rec- 
ommend operating temperatures of up to 
82 F, but it remains a good idea to check 
with your own equipment manufacturers 
before assuming that your data center is 
overheated. It's also wise to understand 
how that equipment interacts with the rest 
of the data center. 

"The first step is to discover the IT infra- 
structure and facilities," says Dr. Mickey S. 
Zandi, managing principal at SunGard 
Availability Services (www. availability 
.sungard.com). "You must understand the 
current state of the infrastructure — ^how is it 
interconnected and independent? By under- 
standing the interdependencies, an organi- 
zation is then able to right-size the infra- 
structure. Next, validate your design layout 
and modify it to meet current trends. 
Carefully plan the change to the topology 
and the interconnectivity." 

According to Rangel, if your data cen- 
ter's temperature needs to be adjusted 



only a few degrees, or if it experiences 
constantly fluctuating temperatures, a 
series of small fixes could satisfy the pro- 
ject. For example, control in/out access to 
the room to harness unnecessary tempera- 
ture fluctuations, and implement spot 
coolers directed at hot spots or to boost 
the current air-conditioning system. He 
also recommends installing one or two 
dedicated AC cabinets for the hottest 
configurations, as well as adding ducts 
and vents to the server room's existing 
AC system. 

Power Down 

Keeping temperatures under control is 
critical for the efficient operation of your 
data center, but undertaking this project 
without regard to power consumption can 
lead to escalating costs. So, while working 
toward temperature management, be sure 
to watch for opportunities to control costs 
through green infrastructure and power 
management systems. 

"Not only does a sustainability, or green 
IT initiative, present a substantial potential 
for cost savings in the face of escalating 
power costs, it offers the data center to 
present its 'green' credentials to cus- 
tomers, co-workers, and affiliates," says 
Steve Kolbe, CEO and founder of 
AnalySys (www.analysys.net). "It also is a 
proactive approach to a likely eventuality 
that the U.S. data center may become reg- 
ulated as cap-and-trade or other similar 
legislation such as the U.K.'s Climate 
Change Levy [a carbon tax] is enacted to 
stem the further growth in consumption." 



Kolbe recommends taking inventory of 
systems presently in place and reducing 
in-production systems where possible. For 
example, you can virtualize servers and 
identify systems that can be eliminated or 
transitioned into a powered-off, or cold 
backup, state. Not only will these steps 
help to keep energy consumption under 
control, but they'll also contribute to the 
overall effort of keeping temperatures in 
check. Kolbe also suggests identifying 
systems that can be targeted for scheduled 
or scripted sleep mode or power-off status. 

Required Resources 

Attacking rising temperatures while 
keeping power consumption in check can 
easily empty a yearlong budget, but that's 
not a given. In fact, some measures can 
help to save tremendous amounts of 
money over time, thanks to a better-run- 
ning data center infrastructure that isn't 
handcuffed by pricey energy costs. 

Rangel says that simple cooling fixes 
can range from several hundred dollars to 
about $20,000 if you purchase several 

Where To Start 



dedicated AC server cabinets or a new 
AC unit. However, if you currently have 
no raised flooring but determine that you 
need it, you could be facing costs of up to 
$100,000 for architectural fees, builder's 
fees, and the product itself. But solutions 
geared toward reducing energy consump- 
tion offer a more cost-neutral proposition, 
because the savings on power costs can 
eclipse the one-time cost of systems 
themselves. 

In terms of personnel, this project relies 
on several parties to help reach a success- 
ful conclusion. Rangel notes that IT staff 
members are required to reroute cables 
and rerack equipment as needed, and facil- 
ities management and staff are needed to 
move equipment, add AC ducts, and place 
tighter seals and/or controlled access locks 
on entry and exit doors. If new equipment 
is required for the project, vendors will 
also be in the mix. Finally, Kolbe recom- 
mends involving an outside electrician for 
low- and high-voltage wiring as well as a 
consultant qualified in green or sustainable 
technology initiatives. 



Big infrastructure projects should never be tal<en liglitly, particularly because you're dealing with 
the backbone of your data center. Steve Kolbe, CEO and founder of Analysys (www.analysys 
.net), says that it's a good idea to take a slow, deliberate approach to the project. 

"Data centers are expected to function seamlessly 24/7, without outage or incident," he says. 
"Therefore, a proof-of-concept step is appropriate on nonproduction systems. This allows the 
implementer to demonstrate functionality, and it also gives insight into the reality of any anticipat- 
ed cost savings that may have been calculated, or proposed if an outside consultant Is involved." 

Before jumping into the proof of concept, Kolbe says it's necessary to conduct comprehensive 
analysis, which can take at least two months to establish an appropriate average. This analysis 
should depend on a strategy that looks at current inventory and determines where changes can 
and should be made. 



Data Classification 



Continued from Page 1 
is overly accessible. Other metadata for 
classification might be access activity and 
ownership information. 

"What is most important about using 
metadata is that it can be used to separate 
the data that is most interesting from the 
data that is not and thereby accelerate the 
data classification process," says Reich. 
"In this way, the metadata becomes anoth- 
er element of the search. Specifically, it 
provides a short-list of where to look and 
what to expect." 

For example, he notes, if someone 
wants to find poorly protected credit card 

Most Common 
Misstep: Not 
Establishing 
Ownership 

Raphael Reich, senior director of marketing 
at Varonis Systems (www.varonis.com), 
notes that classifying data without knowing 
who owns it is a stumbling block that can 
lead to the problem of finding data that's of 
interest but not knowing the significance of 
the finding. He says, "Yes, it's sensitive 
data, but is it fine where it's stored, or does 
it need to be moved? Are the people who 
access it the right ones, and is this actively 
used data or should it be archived?" Finding 
a data owner can help answer these ques- 
tions, and although it sometimes takes a bit 
of investigation to track down data owner- 
ship, it can prevent improper classification 
and storage. 



data, he or she can first identify those files 
that are poorly protected and then look 
inside them for credit card data. That's a 
faster way to identify data that's at risk 
than to first look for credit card data in all 
files and then determine which of those is 
not well-protected. 

Gather The Leaders 

Although some automation can be used 
once metadata is employed, an IT manager 
will still have to bring together leaders 
from different departments to get a sense 
of what type of data they find important. 

Coming into these types of meetings, an 
IT manager should have metadata infor- 
mation to give insight on what type of data 
is in use and how often data is accessed, 
notes Bob Fine, director of product mar- 
keting at storage provider Compellent 
Technologies (www.compellent.com). 

He states that many department heads 
may not know what type of data is being 
stored and why it's important to prioritize 
the data. These conversations can also get 
tricky, he adds: "One of the biggest chal- 
lenges is how to have intelligent and 
meaningful discussions among business 
leaders, so they can determine whose data 
is more important, relatively speaking, 
compared to others. Of course, most busi- 
ness leaders will claim their data is more 
important than the person across the table, 
so IT needs to be prepared for that." 

Having solid information about access 
and frequency of use creates more intelli- 
gence around usage, Fine notes, and tends 
to curb debate. At that point, the discussion 
can turn to the advantages of tiered storage. 

Another benefit to bringing leaders 
together is that they can identify the key 



Key Points 



• Determine what types of metadata need 
to be collected for the data classification 
process; these might include ownership, 
usage, and access permissions. 

• Bring together the company's business 
leaders to get their thoughts on what 
types of data are most important and 
what's driving data search needs. 

• Establish different levels of sensitivity 
based on content type. 



words, phrases, and patterns that will help 
with deeper classification work, Reich says. 

"You'll need to understand what's dri- 
ving the need to find data," he notes. "For 
example, in many organizations, regulato- 
ry compliance is a driver. Other common 
types of information requiring special 
attention are intellectual property, cus- 
tomer data, and employee information. As 
you work with [department leaders] as 



well as security and risk managers, be as 
specific as possible about what needs to be 
identified and protected." 

Create A Hierarchy 

In terms of setting criteria used for clas- 
sification, experts recommend establishing 
different levels of sensitivity based on the 



type of content an organization needs to 
manage and protect. Industry best prac- 
tices show that a good rule of thumb is to 
constrain hierarchy to four levels, Reich 
notes, because more than that becomes 
difficult and impractical to manage. 

An example of four levels might be: 

Secret data: information critical to an 
organization's core value, including data 
that would be significantly damaging if 
competitors were to obtain it. 

Confidential data: also called regulated 
data, this information is required for stor- 
age due to regulations or to protect cus- 
tomer and employee privacy. 

Private data: information an organiza- 
tion prefers to keep out of the public 
domain but that is considered noncritical. 
An example might be the names of prod- 
uct vendors used by the company. 

Public data: information intended for 
public consumption and acceptable to 
share inside and outside the company — 
for instance, marketing materials or prod- 
uct specs. 



-Varonis Systems' Rapliael Reich 



Many parts of the process can be auto- 
mated by extracting key information 
from data owners, but personal value 
judgments play a vital role. "It's data 
owners who are equipped to make those 
judgment calls more so than IT, which is 
why finding them early on is important," 
says Reich. 



"What is most important about using metadata 
is that it can be used to separate the data that 
is most interesting from the data that is not." 
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Visit our Website at 
www.liergo.com to learn 
% more about our products. 
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Command Centers 
Control Stations 
PACS- Mobile Carts 



Enclosures and Cabinets 
Relay Racks 
Flat Panel Monitor Arms 
Motorized Work Stations 





ergo^ 888.222.7270 www.hergo.com 
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Prepare For The Unexpected With Room Alert 



^ || o one knows when or how disaster will 
.strike. We just know the potenliiil is always there. 
So preparation is crucial lo minimizing its impact 
on computers, networks, users & business. 

When disasters occur, there are significant 
costs in ar^cas that go far beyond the simple 
replacement ofdamaged hardware. This is 
because what happens in the data center or other 
facility effects the entire organization. If disaster 
strikes your racility, how will it impact business? 
Who will gel the blame? Could it have been 
prevented? What will it cost? 




Siilutittns 

Stan At $195 



Room Alert products can niniittnr: 

• Temperature • Smoke /Fire 
' Humidity 

• Heat Index 

■ Main/ UPS Power 

• Flood /Water 
' Room Entry, Motion 

■ IP NetworK Cameras 



Air Flow 
Sound, Light 
Panic Buttons 
Dry Contacts 
Switch Sensors 
Wireless S More 



AVTECH has a full line of powerful, scalable 
Room Aleri solutions for real-time 
environment monitoring in a computer room, 
data center or other facility. All models 
arrive assembled with easy to in.stall 
hardware, cables, sensors, easy-to-use 
logging & alerting software, printed 
documentation, unliinited technical support 
and a '30-Day Satisfaction Guarantee'. Users 
can typically install in under 10 minutes. 

Room Alert products monitor critical 
environment conditions like temperature, 
power, humidity, flood, smoke, room entty, 
air flow, motion and more, alert stalTby any 
iTiethod and can take automatic corrective 
action. There is a model that is right for any 
organii:ation and budget... yours too! 

Call or Visit Us Online Today 



2&AVTECH 



888.220.670Q • 401.628.1600 
AVTECH.com 



Protect Your IT Facility... Don't Wait Until It's Too Late!' 
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How Do You Measure the Ener 
Efficiency of Your Data Center? 




WEB BASED SPM INTERFACE 



SENTRY POWER 
MANAGER APPLIANCE 

" ' la 




Sentry Power Manager 

> Enterprise Cabinet Power IVIngt. 

> Reports & Trends 

> Device Monitoring 

> Groups & Clusters 

> Kilowatt Readings for Billing 

> Auto-Discovery of Sentry CDUs 

> Alarms 



PRIMARY ETHERNET PIPELINE 

WEB BASED CDU INTERFACE 





Sentry: POPS Switched CDU 

With Device Monitoring 

> Rack Level Power Management 

> Outlet Power Monitoring (POPS) 

> Input Power Monitoring 

> Environmental Monitoring 

> Outlet Groups 

> Alarms 



ith Sentry Power Manager™ (SPM) 
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Sentry POPS (Per Outlet Power Sensir 



V Server Technology 



Solutions for the Data Center tf 1.800.835.1515 www.servertech.com 

Equipment Cabinet tel 1 .775.284.2000 sales(aservertech.com 
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For more Upcoming IT Events, see page 3. 



Cincinnati .NET 
Users Group 
Feb. 9, 6 p.m. to 8:30 p.m. 
IVlax Teciinical Training 
4900 Parl<way Drive, Suite 160 
fVlason, Ohio 
www.maxtrain.com 



PASS Wisconsin SQL Server 
User's Group 
Feb. 9, 4:30 
IVIicrosoft Office 
21 76 Woodcrest Drive 

Green Bay, Wis. 
wisconsin.sqlpass.org 



AITP San Diego 
Feb. 10, 5:30 p.m. 
National University-Kearny IVlesa Campus 
3678 Aero Court 
San Diego, Calif, 
sandiego. aitp.org 



Greater Wlieeling AITP 
Feb. 10 
Wheeling, W.Va. 
www.aitp-wheeling.org 



ISSA San Diego 

Feb. 10 
www.sdissa.org 



AITP Washington D.C. 

Feb. 11, 6:30 p.m. 

Alfio's Restaurant 

4515 Willard Ave. 

Chevy Chase, Md. 
aitpwashdc.ning.com 



AITP Southwest Missouri 
Feb. 16 
Springfield, Mo. 
aitpspringfield.org 



ISSA St. Louis Chapter 
Feb. 16 
St. Louis, Mo. 
stl.issa.org 



Oklahoma City AITP Chapter 
Feb. 16 
Oklahoma City, Okla. 
www.aitp.org/organization/chapters 
/chapterhome.jsp?chapter=40 



AITP Northeastern Wisconsin 
Chapter 
Feb. 17, 4:15 p.m. 
Holiday Inn Select 
150 S. Nicolet Road 
Appleton, Wis. 
new.aitp.org 



AITP Atlanta 
Feb. 18, 5:30 p.m. 
Crowne Plaza Atlanta Perimeter NW 
6345 Powers Ferry Road NW 
Atlanta, Ga. 
www.aitpatlanta.org 



ISSA Upstate South Carolina 
Feb. 19 
NuVox 

301 N. Main St., Suite 5000 
Greensville, S.C. 
www.upstate-issa.org 



ISSA Des Moines 
Feb. 22 
3920 SW Camden Circle 

Ankeny, Iowa 
www.jssa-desmoines.org 



AITP Akron 

Feb. 23 
Akron, Ohio 
www.akron-aitp.org 



First Look Visual Studio 2008 
Feb. 24, 8 a.m. to 4 p.m. 
Max Technical Training 
4900 Parkway Drive, Suite 160 
Mason, Ohio 
www.maxtrain.com 



ISSA Baltimore 
Feb. 24, 4:30 p.m. 
Sparta Inc. 
71 10 Samuel Morse Drive, Suite 200 
Columbia, Md. 
www.issa-balt.org 



AITP California Southland 

Feb. 24 
www.aitpcalsouthland.org 



COVER FOCUS 



Better i 
Mobile 
Storage 

Make 2010 The Year Your 
Mobile Storage Gets Bulletproof 




by Elizabeth Millard 
• • ■ 

As THE NEW DECADE dawns, employees 
are more mobile than ever, and the type of 
cobbled-together storage systems that 
might have sufficed just a few years ago 
are no longer sufficient for the years 



Key Points 



• Create as much standardization as possi- 
ble when approaching mobile storage, 
because using multiple device brands can 
create troubleshooting headaches. 

• Tap into automation as a way to bring all 
aspects of a storage strategy together. 

• Develop a data recovery strategy that is 
specific to mobile computing. 



ahead. Instead, make a resolution for 2010 
to develop a multilayered, secure, and for- 
ward-looking mobile storage strategy. 
Here are some key elements. 

Standardization 

Mobility experts have often touted the 
benefits of having a company on a single 
mobile platform and standardizing de- 
vices. If an SME hasn't taken that route in 
the past couple years, this could be the 
year to get started. 

With such an increase in mobility, an 
array of device types and brands can cre- 
ate troubleshooting issues, not to mention 
compatibility concerns. One type of smart- 
phone might sync well with a storage 
application, while another requires several 
extra steps to get to the same point. More 
importantly, standardization helps with 
security because storage and security are 
so closely linked. 

Automation 

Utilizing change and configuration 
management tools can boost the ability to 
back up data automatically, notes Grant 
Ho, senior solutions marketing manager 
for endpoint management at Novell 
(www.novell.com). 

He notes that when combining standard 
backups with mobile storage, automation 
is necessary so that users don't have to be 
relied upon to do nightly backups them- 
selves. Instead, a data center manager can 
set a policy that the devices or laptops are 
backed up whenever they're connected to 
the local network. 

Automation can be used, as well, for 
replicating data to a second or third loca- 
tion beyond the corporate data center, adds 
Chris Winter, director for CDP product 



management for SonicWALL (www 
.sonicwall.com), developer of backup 
and security products. 

"Backed-up data must somehow be 
replicated to a second, and geographi- 
cally separate, location," he says. 
"Replacing a failed disk drive and 
recovering all of the operating sys- 
tem, applications, configurations, and 
preferences takes the same time on a 
desktop as on a mobile device, usual- 
ly two to three days. A good mobile 
backup solution will recover a failed 
disk drive in less than four hours for 
both desktop and mobile devices." 

The best mobile backup solutions 
will allow the backup to be stored or 
restored to a physically or virtually 
different device in case of loss or 
technology changes, he notes. Auto- 
mation allows for better sync between 
a data center and mobile devices, creat- 
ing a single data warehouse rather than 
data silos. 

Data Recovery 

The ability to bounce back from a disas- 
ter, such as an unexpected outage, is cru- 
cial for any storage strategy. When it 
comes to mobility, IT managers have to 
consider lost and stolen devices, system 
file corruption, inadvertent file deletions, 
and other common data loss events. 

"What we've found is that about 
85% of data loss issues aren't mechani- 
cal," says Gary Streuter, vice president 
of marketing at CMS Products (www 
.cmsproducts.com). "Maybe someone's 
kid went on their work laptop and erased 
something, for example, or an employee 
downloaded a program that caused prob- 
lems. That's when you need a solid res- 
cue strategy." 

He notes that the traditional approach at 
many companies has been to have far- 
flung employees box up a machine and 
send it in, but the lost productivity can be 
detrimental. If an employee can come into 
the office, it's less of a hit, but in many 
cases, there's at least some downtime. 

At some backup providers, recovery 
takes the form of portable data backup 
products with disaster recovery software 
built-in. The unified products allow for 
both documents-only backups and full- 
system storage. 

Other appliance and software develop- 
ers also have options that combine data 
recovery with backup features. When 
evaluating different products, it's vital to 
ask vendors how well they might match 
with existing corporate mobile devices and 
evaluate user education training materials 



available from vendors. Most im- 
portant, though, is simply to have 
data recovery as a robust part of a 
storage strategy. 

User Education 

Although every aspect of storage 
will rely heavily on IT, and auto- 
mation should take users out of the 
equation to some degree, employ- 
ees will have a certain level of 
involvement when it comes to mo- 
bile backup. 

Letting users know what to expect 
can go a long way toward creating 
user comfort with storage proce- 
dures, notes Streuter. Also, using 
analogies from the nontechnical 
world can be useful. For example, 
he suggests that users be told they 
can run off an external unit but shouldn't 
work on it for long, "much like the drive is 
the spare tire for a car, but when you're 
running on a spare, you better not have 
another flat," he says. 

Developing user-friendly training 
materials is one option, but you should 

Where To Start: 
Get An Overview 

Like any major technology implementation, 
the first step is to organize data in order to 
see where standardization makes sense. 
With mobility, that means creating a spread- 
sheet that tracks what types of devices — 
such as laptops and smartphones — are 
being used, how data is being accessed, 
and what type of storage is needed. 

Before putting pieces in place, talk to ven- 
dors and other data center managers to get 
an idea of the different types of storage 
implementations that have been done and 
garner details on any challenges or mis- 
steps. Then, run a test or pilot program to 
find any initial stumbling blocks before 
rolling the program out company-wide. 



also draw on vendors for information; 
often, product developers have well- 
written FAQ sheets that can be used 
for implementations. 

With major steps such as user educa- 
tion, standardization, and automation in 
place, SMEs can be more confident in 
creating a storage strategy that includes 
mobile devices, and as the decade rolls 
on, scalability and growth won't be 
sources of anxiety. 
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News 



I Former Seagate Employee 
Blows Whistle 

Former Seagate employee Paul Galloway 
has alleged in legal documents that Seagate 
is guilty of using intel- 
lectual property 
owned by Con- 
volve in its hard 
drives. The 
legal docu- 
ments are part 
of a 9-year-old 
patent infringe- 
ment lawsuit 
brought against 
Seagate by 
Convolve. 
Galloway 
says that he 
saw developers at Seagate using Convolve's 
Quick and Quiet technology, which pertains 
to drive-silencing techniques that stifle noise 
and vibration within hard drives, and that the 
evidence had been destroyed by Seagate. 
The Massachusetts Institute of Technology is 
also a plaintiff in the suit, which asks for $800 
million from both Seagate and Compaq. 

I McAfee Outlines Biggest Threats 
In 2010 

Security experts at McAfee believe that hack- 
ers and malware makers have shifted their 
focus from primarily Microsoft products to other 
software platforms, such as Adobe's Flash and 
Acrobat Reader programs. McAfee's 2010 
Threat Predictions report points to improved 





security in Microsoft's software and the rising 
popularity of Adobe's offerings as reasons for 
the criminals seeking out new avenues of 
attack. Other targets feeling the brunt of the 
shifted focus include Mozilla's Firefox browser 
and Apple's QuickTime software. The report 
also warns of increased attacks on social net- 
working sites such as Facebook and Twitter as 
well as HTML 5-based and Google Chrome 
OS-based attacks throughout 2010. McAfee 
also acknowledges that improved international 
and domestic law enforcement collaboration 
and tactics will lead to more cyber criminals 
behind bars in the coming year. 

I Court Bans Current Versions 
Of Microsoft Word 

Microsoft lost another round in its fight to 
keep selling Microsoft Word in its original 
form. In 2007, Canada-based 141 filed a law- 
suit against Microsoft for including some of 
its technology, designed to enable users to 
easily edit XML documents, in Microsoft 
Word. Microsoft lost that round and was 
ordered to stop selling Word and pay fines 
totaling $290 million. The software giant 
appealed the decision, and a federal appeals 
court has just found that, indeed, Microsoft 
did violate i4i's software patent. As a result, 
Microsoft will be forced to cease selling Word 
as of Jan. 1 1 and pay the damages. Ver- 
sions of the offending software sold prior to 
that date will not be subject to any specific 
action, but versions of Word 2007 and Office 
2007 sold after Jan. 1 1 will not include i4i's 
software. Future versions of Word and Office 
expected in 2010 also do not include the 
software. Microsoft has yet to state publicly 
whether it plans to seek further appeal. 
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Your 2010 
Security 
Proj ect 

Make End-User Responsibility 
A Priority In The New Year 



by Carmi Levy 

As IT SHOPS REFINE their priority lists for 
security-related investments in the coming 
year, reducing client-side risk is emerging 
as a leading — and cost-effective — option. 
As appealing as big-bang investments in 
high-profile security hardware such as 
firewalls and dedicated appliances might 
seem, the smarter option for resource- 
constrained organizations typically involves 
process-focused projects that reinforce 
end-user responsibility for data. 



Key Points 



Resist the urge to buy new security hard- 
ware or software; instead, focus on human 
factors to improve data management prac- 
tices and reduce risk of exposure. 
Segregate sensitive client machines and 
lock down PCs used for especially sensitive 
functions such as banking and payroll to 
limit exposure to targeted malware attacks. 
If your shop lacks in-house security exper- 
tise, look to third-party security consul- 
tants to help assess current state and 
longer-term needs. 



"Most security-related risks within com- 
panies are caused by user error," says Jack 
Gold, president and principal analyst of 
J. Gold Associates. "Companies lose data 
because they don't do a very good job of 
telling their users what they should be pro- 
tecting, how they should be protecting it, 
and how they'll get them onside to accom- 
plish that." 

People Matter Most 

Gold says companies in the process of 
narrowing down their security project lists 
for 2010 may want to stress human factors 
instead of technology acquisitions. 

"From a cost perspective, especially for 
SMBs, a lot of what they need to do is not so 
much around upgrading software or hard- 
ware," says Gold. "In most cases, it's more 
important for them to assess what their risks 
are and what their end users can do to help 
them mitigate some of those risks." 

On a day-to-day level, these risks may 
involve vulnerable client-side machines. 
These vulnerabilities, often in the form of 
malware, can silently compromise corporate 
desktops and result in the exposure of sensi- 
tive financial data. 

Kaspersky Lab security evangelist Ryan 
Naraine says the Clampi Trojan, which 
specifically targets banking information, is 
already responsible for more than $40 mil- 
lion in losses over the past two years. He 
says it reinforces IT's need to tighten 



security around machines used for finan- 
cial transactions such as banking, payroll, 
and retail or point-of-sale activities. 

"This is an ongoing problem that up until 
now has been under-reported," says 
Naraine. "It's a big problem because IT 
departments are under-resourced and under- 
funded, especially because of the recession, 
so they're less likely to be doing the kinds 
of things they need to do to identify the 
problem and obtain funding to solve it." 

Naraine says this class of malware 
specifically targets these dedicated, trans- 
action-focused machines, so hardening 
these systems is an effective first step. 
Beyond the obvious best practices applied 
to any client PC — fully patched and updat- 
ed operating systems and applications, 
fully updated antivirus and anti-malware 
packages, and monitoring systems tuned 
to detect anomalous behavior — he recom- 
mends strictly controlling the build. This 
includes removing the email client, 
removing the browser (or at least running 
it without add-ons or extensions), limiting 
everyday Web activities, and outright for- 
bidding social media activities. 

"These machines should support only 
the activities required to handle the trans- 
mission and storage of confidential finan- 
cial, personnel, or similarly sensitive data," 
says Naraine. "This limits their exposure to 
these kinds of focused attacks." 

Beware Of Social Media's Pitfalls 

If social media and other broader-focused 
Web activities are integral to a particular 
employee's role, they can be delivered via 
separate client machines. Phil Schacter, vice 
president and service director for security 
and risk management strategies at Burton 
Group, says reinforcing smart social media 
data usage policies can save organizations 

Where To Start: 
Assess Your Risks 

You can't improve what you don't know. 
Assess your existing end-user security 
maturity to establish a baseline. Quantify 
risk factors associated with identified gaps — 
for example, the potential for social media- 
aware employees to breach privacy or for 
road warriors to misplace USB drives. 

Finally, match solutions to each risk — for 
example, limits on social media activities not 
directly related to a given role or mandated 
use of encrypted removable media and lim- 
its on database mobility off of the protected 
corporate network. Once cost/benefit is cal- 
culated for each, prioritize and proceed. 




from 
embarrass- 
ing and expen- 
sive breaches. 

"It's a growing vec- 
tor for leakage of cor- 
porate information, these 
various social media 
channels," says Schacter. 
"That can be very problem- 
atic, especially if you're a 
public company. The last 
thing you want is to deal with 
employees sharing insider infor- 
mation on Facebook." 

Updating the organization's 
acceptable use policies and inte- 
grating them into the HR-led per- 
formance management framework 
will reduce these gaps. 

Small Cost, Big Impact 

The good news for budget-weary IT 
departments is these types of projects 
rarely break the bank. 

"In many cases, it's leveraging the exist- 
ing investments you've already made," 
says Schacter. "The information that 
you're looking for to reduce your expo- 
sure may not require you to purchase new 
software or a new appliance. You may 
already be recording it [with] a product 
you're using for network management." 

The low cost comes with its own risk, 
however, in that senior leadership may not 
buy into the projects' importance. Just 
because security projects such as this 
don't require major investments doesn't 
mean they're not significant to the organi- 
zation's bottom line. Shorter timelines for 
human- and process-oriented security pro- 
jects also drive earlier reduction of risk 
and ultimately greater ROI. 

Once approved, IT should resist the urge 
to handle them as ad-hoc initiatives. They 
should instead be managed as de facto 
projects, with the same degree of project 
management rigor also used for big-ticket 
technology projects. 

Know What You Have 

Closing the gaps in end-user security 
involves understanding your current 
state — something that's easier said than 
done given the general state of security 
awareness in the average SMB. 

"Very few companies actually do true 
security assessments," says Gold. "You need 
to look at the assets you're trying to protect, 
do a real assessment of what your security 
risks are, and then put a strategy around that 
to protect yourself. It's relatively inexpen- 
sive, but companies often ignore it." 

Although vendors are often only too 
happy to help with assessments. Gold rec- 
ommends companies with limited in- 
house security expertise consider working 
with third-party experts. 

"It's worth paying a bit of money up 
front to bring in someone to do this for 
you," says Gold, who adds that an indepen- 
dent consultant is more likely to provide 
independent, vendor-neutral advice. 
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Migrate Smoothly 
) To Windows 7 



When it comes to New 
Year's resolutions, jumping 
on the new OS bandwagon 
isn't exactly something an SME 
should do without consideration. 
Although your enterprise may be 
considering the switch to Windows 7 
in 2010, you first need to know what 
you'll gain from the switch, what's 
involved, and what kind of investments 
you'll need to make. Here's a rundown of 
what the experts are advising when it comes 
to switching to Win? this year. 

Why The Change? 

Mike Temple, product manager at Avo- 
cent (www.avocent.com), says any Win? 
migration project should start long before 
you unwrap the installation disc. Temple 
says the first question that must be answered 
is, "Why migrate?" He says that, fortunately, 
in the case of Win?, Microsoft answers this 
one for us. "For starters, Windows XP is 
eight years old this past October, and unless 
you have an expensive enterprise agreement 
or software assurance, support is dwin- 
dling — not to mention that hardware manu- 
facturers are no longer writing drivers for XP 
for new hardware coming out," he explains. 

Where To Start: Ensure 
Hardware & Software 
Compatibility 

Once your enterprise has decided to switch 
to Windows 7, there are a number of steps to 
tal<e. Here are a few important steps, as out- 
lined by IVIike Temple, product manager at 
Avocent (www.avocent.com). 

• Look for systems that do not meet the rec- 
ommended minimum specifications as 
outlined by IVIicrosoft. In other words, if 
you upgrade a perfectly good Windows 

XP machine running your "big business" I 
application, will the overhead of Win7 
cause the application performance to suf- 
fer and be subpar? 

• Lay out a hardware refresh program. New 
systems and systems that are refreshed as 
part of a regular hardware refresh cycle 
should factor into the migration. Be sure 
that your new machine acquisition process 
includes Win? when it rolls in the door. 

• Perform an analysis of applications that 
can run on Win?, and for those applica- 
tions that cannot run (or do not function 
properly or completely), there are three 
options for applications that have issues: 
compatibility mode, WinXP mode, and an 
upgrade to a Win7-compliant version. 



M Bob Kelly, senior prod- 
^mM uct manager at KACE 
(www.kace.com), says the 
primary reason for SMEs to 
make the switch is security 
improvements. Security is not only 
improved, he says, but also better 
implemented. Kelly says newer systems 
will not offer WinXP as an option much 
longer, so Win? will likely start making its 
way into most environments soon. "Micro- 
soft is still likely to provide stubborn XP 
users with more major security-based plat- 
form updates beyond this date — especially 
when the XP Mode in Windows ? actually 
requires a background virtual machine run- 
ning XP in its entirety," he says. "As much 
as Microsoft tries to leave XP behind, it 
seems its tentacles will be holding on for 
some time to come. However, that doesn't 
mean one can avoid Windows ?." 

Getting Involved 

Before the big migration, there are a num- 
ber of things to consider, according to 
Temple. "IT staff should be aware that an in- 
place migration for Windows ? is not sup- 
ported from Windows XP (which 80% of the 
companies worldwide still use), and it is 
required that you first upgrade to Vista and 
then upgrade to Windows ?," Temple says. 
"An in-place migration does not clean up a 
machine that has old applications, but it 
should do a good job of making sure all data 
remains intact post-upgrade." 

Temple says most organizations have a 
robust load process anyway, which he says is 
simply a load process with a step beforehand 
that captures user data and a step afterward to 
restore the same data. "A reload cleans and 
optimizes the machine as much as possible 
for the new OS." 

When making the switch, Kelly says all 
new software must be tested for compatibili- 
ty with the new OS. "From there, the project 
is largely a matter of mastering the tools to 
be used in the deployment," he explains. 
"And with most moving from XP, the only 
option is a clean slate, although I would not 
recommend that a corporate network take 
advantage of an in-place upgrade option any- 
way." Kelly says IT should also be aware 
that rolling out a new OS requires either a 
scripted, unattended installation of the new 
OS or the deployment of a drive image. 

Kelly also says it is a good idea to engineer 
an automated installation process as the 
source for a Win? deployment, even if the 
plan is to ultimately deploy it through an 
imaging solution. "Technically, the Windows 
installation itself is a file-based image, so the 
distinction is more subtle today than it was 
when XP was deployed," he says. "To put it 
simply, a scripted installation uses an answer 
file to automate the installation process." 

The Investments 

In Kelly's opinion, although there are free 
migration tools available from Microsoft, 
they can be complex to configure and there- 
fore may require a higher level of expertise 
than many small to midsized enterprises have 
at their disposal. The biggest expense may be 
the purchase of a third-party deployment 



Steps To Take If A New OS Is In The Cards This Year 



solution to give the project a better chance of 
success. "But that cost can be well-justified," 
he notes, "and a return on investment should 
be possible in the course of a single migra- 
tion project like this by eliminating much of 
the training, time, and potential frustration 
required when performing such a migration 
without the proper tools." 

The time migration takes from start to fin- 
ish can vary greatly, not only because of the 
size of the network and complexity of the 
environment, but also because of the tools 
used. For example, Kelly says although some 
solutions can be implemented quickly, some 
tools that require server configuration and 
installation of dependencies through an envi- 
ronment can sometimes take months. 

Temple says that while the technology 
analysis is going on, SMEs should consider a 
user-training mechanism. "This should be 
either in-person, online, or whatever works 
for your particular user base," he says. "Keep 
in mind that the user interface is different, 
and Windows ? has functions that may or 
may not affect the user experience. Account 
for the spectrum of technical diversity within 



Key Points 



Migrating to Windows 7 will soon become 
a necessity as support for Windows XP 
begins to dwindle. 

Before migrating, ensure that important 
applications are compatible with Win7. 
Migration may be complicated, so consid- 
er using a third-party migration tool and 
be sure to adequately train users ahead 
of time. 



your user base and attempt to train the user 
close to the time their workstation will be 
upgraded to minimize retraining." 

No matter what happens, both experts 
agree that users will gain from migrating to 
Win?. Kelly concludes, "While security 
improvements are probably the biggest factor 
for businesses, Windows ? also offers 
improved performance and is better capable 
of taking advantage of today's new hardware 
improvements — especially when compared 
to Windows XP." 
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Cisco Annual Report 
Shows Spam, Attacks 
On The Rise 

Untargeted spam and attacks on social net- 
working sites are on the rise and quickly 
becoming significant global threats, accord- 
ing to Cisco's 2009 Annual Security Report. 

According to the report, social networking sites 
based on Web 2.0 technology can be easily 
exploited by online scammers. "Social media 
has become a playground for cybercriminals," 
says Henry Stern, senior security researcher 
at Cisco. Criminals spread malware by first 
taking control of an account and then sending 
a malware-laden message to that account 
holder's contacts. Attackers utilize social engi- 
neering to let account holders do the work of 
spreading malware for them by relying on the 
principle that a user will automatically open a 
message sent from someone they view as 




trustworthy. For the same reason, social net- 
working sites are also vulnerable to phishing 
attacks. Cisco's report recounts three separate 
phishing attacks launched against Facebook in 
a single month. 

According to Stern, one of the most surpris- 
ing findings of the study was the increase in 
the amount of spam during 2009. "Brazil has 
topped the United States as the leading 
source of spam," Stern says. "It was the 
result of a highly successful broadband initia- 
tive in Brazil, connecting 80% of the popula- 
tion. High rates of piracy and low adoption of 
antivirus created a situation of connectivity 
without security," he says. 

Cisco's report highlighted other threats, 
including "spamdexing," where criminals 
push their false or malicious Web sites to 
the top of search engine results lists; the 
Conficker virus; botnets; and data loss. 

Lessening The Threat 

"User education is key, not only of the ways 
criminals attack organizations, but of the true 
financial losses and consequences to reputa- 
tions resulting from a compromise," says 
Stern. "Network instrumentation, such as with 
an intrusion prevention system or botnet traf- 
fic filter, can help reduce the risk of data loss, 
including the exfiltration of login details of 
online financial systems by threats such as 
the Zeus Trojan," he adds. 

Cisco's report includes recommendations for 
organizations on how they can protect their 
enterprises. Cisco's recommendations in- 
clude not only user education and security 
awareness training, but also watching older 
machines that can be more easily infected, 
never underestimating insider threats, and 
putting in place strong policies for protecting 
sensitive data. 

by Kris Glaser Brambila 
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HOW TO 



Effectively Cool 
A Small Data Center 

Smaller Spaces Are Less Forgiving & Need More Attention 



by Curt Hurler 

It may be more important to ensure 
good cooling in small data centers than in 
big ones. John Consoli, CTO at AFCO 
Systems (www.afcosystems.com), draws 
an analogy to protecting fine cigars. "The 
cigars I keep at my cigar club are pre- 
served in a big, walk-in humidor. I have 
never had one go bad on me there," he 
says. "Yet, if I neglect the small humidor I 
keep in my office for even a few days, I 
will have a bunch of dried tobacco sticks! 
The smaller the environment, the less tol- 
erance for error." 

How cool it would be to start 2010 with 
a program to reduce energy consumption 
in all your small, remote data centers, sav- 
ing 25 to 50% of power costs. The place to 
start is with airflow management. 

"Proper airflow is the key," says 
Consoli. "Most IT equipment will operate 
just fine at temperatures up to 90 degrees 
[Fahrenheit] as long as the surrounding air 
is kept moving. With so many environ- 
mentally controlled racks available on the 
market, it does not make sense not to con- 
sider such an investment." 

Some studies put the dividing line for 
determining whether advanced cooling 
practices are worthwhile between the 
place where a room generates 6kW or 
more per cabinet or runs at 4kW or less 
per cabinet. But do not discount the ability 
to get big results in a small data center. 

Lars Strong, P.E. and senior consultant 
with Upsite Technologies (www.upsite 
technologies.com), warns that cold aisle 
containment and hot aisle containment are 
not panaceas. "Even with cold aisle con- 
tainment, having the right number of per- 
forated tiles in the cold aisle is very 
important," he says. 

"SMEs need to accept and appreciate 
the fact that they need to invest in a 
proper computer room or data center. 
Putting a server cabinet in the pantry or 
in a broom closet will cost more in the 
long run," Consoli says, emphasizing 
that IT equipment must be installed in a 
proper environment. 

First Steps 

Mechanical cooling equipment con- 
sumes the vast majority of power used in 
small to midsized data centers. So, you 
should start by improving the cooling effi- 
ciency when initiating a plan to reduce 
costs, says Strong, noting that airflow 
management and cooling tuning are pri- 
marily one-time costs. 

"Potential savings make for a com- 
pelling case to get started," he says. 
"Particularly given the economic climate, 
finding ways to optimize your existing 
equipment is critical. While there may be 
little budget to buy additional equipment, 
spending the money to optimize can not 
only improve your bottom line but reduce 
your carbon footprint." 

"Airflow management can actually 
make more sense in smaller data centers," 
agrees Consoli. "The less cooling air 
we have, the more we need to manage it 



effectively. There is less tolerance for 
waste in a smaller system than in a larger 
one, although the overall cost may lead us 
to think otherwise." 

"If my company had only a single rack 
of servers, I would make that rack an 
active airflow system," he adds. 

Before implementation, you should 
understand loads, capacities, and the envi- 
ronment. Strong says, emphasizing that 
understanding all three is necessary to iden- 
tifying the path to take to improvement. 

Other key factors include summed rated 
cooling capacity (CCF), total IT load, and 
identification of hot spots (temperatures 
exceeding maximum set by site manager). 
Once this data is collected, the cooling 
capacity factor can be determined. 

"The CCF indicates how much room 
there is for improvement, how much 
money can be saved, and how much the 
environment (air-intake temps) can be 
improved," Strong explains. He recom- 
mends following ASHRAE standards, 
which specify 80.6 degrees Fahrenheit. 

Find A Solution 

Strong says the best solution is the sim- 
plest one: Manage what you already have. 

"Once this is done, there are many good 
ideas, including cold aisle containment, 
hot aisle containment, etc., that are very 
useful. What is right for you depends on 
the unique conditions of your site," he 
says. However, if the wrong products are 
used, there are ongoing labor requirements. 

Consoli says SMEs should first focus on 
the tools they already have: eyes, ears, and 
hands. "Take a walk through your data 
center and observe where heat is produced 
and how cooling is provided," he says. 
"Invest in an ASHRAE TC 9.9 guide for 
best practices in data center cooling and 



TOP TIPS 



• start with airflow: "Improved airflow man- 
agement is the simplest and lowest-cost 
way to increase efficiency in a data center," 
says Lars Strong, senior consultant with 
Upsite Technologies (www.upsitetech 
nologies.com). "The impact of bypass air- 
flow (lost conditioned air) is often underesti- 
mated, or its existence is outright denied." 

• Evaluate your needs by assessing where 
the hot spots are and evaluating existing 
cooling methods. 

• Cover holes in walls and raised floors, 
install blanking panels, and remove air- 
flow obstructions. Upsite's KoldProfile 
Financial Impact Study, which examines 
the energy savings after sealing IT equip- 
ment cabinets with blanking panels, 
showed up to 29% in annual operating 
cost savings and simple payback in a few 
short months. And that was just one step. 

• Implement the right tools: If you invest in 
ones that are ill-suited to your environ- 
ment, you might end up paying for main- 
tenance costs. 



Key Points 



Keep in mind that effective cooling might 
not require new equipment but responsi- 
ble use of existing equipment. 

Don't go cheap: Even small sites should 
invest in a proper computer room. 

Walk through your data center and 
observe where it is hot and cool. 



check to see that these practices are being 
followed in your data center." 

Although he knows SMEs are flooded 
with many "best" practices concepts fly- 
ing around these days, he says most of 
them are related to airflow management 
or isolating conditioned supply air from 
exhaust air. 

Finally, cover any non-engineered holes 
in walls and raised floors, install blanking 
panels, remove airflow obstructions, use 
fans to manage airflow, and set ther- 
mostats properly. 

Yes, It's Worth Doing 

"The possible energy savings are enor- 
mous," Consoli says. He points to clients 
who have cut electricity bills by 30%, 
40%, and even 50%, just by implement- 
ing best practices and focusing on air- 
flow management. 

Strong has a list of ways to improve 
cooling efficiency, starting with bene- 
fits from improving the efficiency of 
the cooling infrastructure — particularly 
by improved airflow management. He 
says SMEs will see increased capacity, 
improved IT reliability, reduced energy 
costs, and deferred capital expenditure. 

There are pitfalls, however. The big one 
experts see too regularly is investing in 
costly management tools without a plan 
for actually using them. The flip side is 
getting too caught up in efficiency for effi- 
ciency' s sake. 

Consoli admits that data centers can 
often be the least green things on the plan- 
et. "This does not mean that our industry 
should not be mindful of managing 
resources," he says. He contends that 
SMEs should focus on maximizing perfor- 
mance. "Get the most out of what you've 
already got before you look to add more," 
he says. Consoli says most of the calls he 
receives about "lack of cooling" in the 
data center turn out to actually be "poorly 
managed" cooling. 

"These data centers have more than 
enough cooling, it's just being wasted," 
he says. 

Although it will cost some time, Consoli 
says it is absolutely worthwhile to work on 
data center cooling. "There is never a 
dumb time to do a smart thing," he says. 
Many of the things SMEs call "efficiency" 
are actually "sustainability." 

"Sustainability is a process, not an event," 
Consoli adds. "Recurring investments will 
always reap the greatest dividends. IT man- 
agers should budget for 'sustainability' in 
their data centers," he concludes. 



January 15, 2010 



Processor.com 



Page 13 



33 Modi, k tu m 




Control and Circuit [VIetering-IVIRP 







1 o 

<* 


OK 
1 


©; 








l\ 


o 








OfF 




SENSOR IWPUIS 



Unique Features 



{ All Circuit Breakers Monitored 

Most metered power solutions only monitor input power. BayTech 
monitors all circuit breakers and reports via SNMP when thresh- 
olds are met. 

{ Optional Outlet Metering with Efficienoy 

Monitor individual outlets and receive current, watts, and volt- 
amps. Continuously monitoring equipment for efficiency with 
power factor. 

{ High Retention 013 Receptacle 

Reliable integrated locking clips assure power cord retention. 
Unique to the industry and does away with nuisance wire clips. 

{ Reliable ROB Rower Distribution 

ISO's (Insulation Displacement) connectors are faulty and unreliable! 
All BayTech power solutions use reliable PCB power distribution. 

{ Integrated Sensor Inputs 

Eliminate the need for extra environmental monitoring devices. All 
BayTech power solutions offer two ports for external temperature 
and humidity probes. 



Build Custom Power Solutions 
with Standard Modular Product 

Bay Tech's MRP Modular Rack Power system provides reliable power 
distribution with maximum flexibility for receptacle selectionand power input. 

BayTech offers three classes of the MRP system. Switched and monitored, 
simply monitored and individual receptacle monitoring. 

User friendly interface for controlling power to receptacles, monitoring 
Current, Voltage, Watts, Temperature, Humidity, and KW Hour Meter. 



Standard Features 

• High and Low Density Models 

• 120/208/AC Single Phase 

• 208/400VAC Three Phase 

• 20,30,50,60 Amp Support 

• On/Off Reboot Control 

• HTTPS,SSH, SSL Access 

• Radius, TACACS Authentication 

• Tool less Mounting 



Unique Features 

• Modular Design 

• All Circuit Breakers Monitored 

• KW Hour Meter 

• Current, Voltage and Watt Meters 

• Integrated Locking C13 Receptacle 
(Optional) 

• Reliable PCB Power Distribution 



Bay Technical Assoc. Inc. 5239 A Avenue Long Beach, MS 39560 Tel: 228-563-7334 Fax: 228-563-7335 sales@baytech.net 



Processor Showcase 

The Processor Showcase provides a 
quick glimpse of data center products 
available from some of the industry's 
leading manufacturers. Each Showcase 
provides information on the product's 
most important features, complete with 
a product photo, to simplify your 
buying process. 



Product manufacturers and resellers: 

To list your products, call (800) 247-4880. 



Physical Infrastructure 




CS-2HD2/HDE Smart Power Monitor 

Easily add input current load and power monitoring to any 
existing cabinet 

Quickly added to SAN's or other cabinets that do not have 
any power monitoring capabilities 
Measure aggregate current draw on each power circuit 
IP access and security/Environmental monitoring 
Provides automated SNMP-based alarms or email alerts 



Server Technology 

Saluiiixr. br 'i'n D^y Career £i;jipm«nt Cablral 



Server Technology Inc. 

(800) 835-1515 
www.servertech.com 



Physical Infrastructure 



CS-3AVY Sentry Smart CDU 

Provides reliable 3-Phase 
power distribution. Multiple out- 
let types distribute multiple volt- 
ages via 3-Phase 208V Wye 
power in-feed. 

• High Density 

• Multiple Voltage Outputs 

• Input Current Monitor 

• IP Access & Security 

• SNMP Traps 

• Environmental (Temperature 
& Humidity) Monitoring 

• Branch Circuit Protection 

• NEW! Linking for Smart 
CDU (Expansion Modules) 




Server Technotosy^ Inc. 



Server Technology Inc. 

(800) 835-1515 
www.servertech.com 



Physical Infrastructure 



CW-24V5 Sentry Switched CDU 

Mixed Outlet 3-Phase 
415V/240V 

• Achieve greater efficiencies 
by bringing 3-Phase 415V to 
the cabinet and 240V to the 
devices 

• Single-power input feed; 24 
outlets per enclosure 

• Delivers up to 21. 6kW 

• Remote power management 

• IP access and security 

• SNMP traps and email alerts 

• Environmental monitoring 

• Ability to add an expansion 
module 






Server Technolosy 



Server Technology Inc. 

(800) 835-1515 
www.servertech.com/products 



Physical Infrastructure 



Snake Tray® Cable Management 
& Power Distribution 

Designed To Reduce Construction Costs! 



Cable IVIanagement 

Built-in mounting hardware 
Integrates with access 
floor or mounts directly to 
the subfloor 

Power Distribution 

Modular energy-efficient 
bus bar technology 
Power and data 
distribution boxes 



Snake Tray 

(800) 308-6788 
www.snaketray.com 






Thanks to DMD, we 
don't have to sit on 
our old computer 
equipment anymore. 



retrieve ■ refurbish - reuse ■ recycle ■ remarket 
We Purchase: We Offer: 



Computers/Laptops 
Networking Equipment 
Power/Environmental 
Telecommunications 
Complete Data Centers 
Printers 



Asset Tracl^ing/Reporting 
Deinstallation/Packing/Transportation 
DOD Level Data Destruction 
Epa Recycling/Reuse 
Ongoing Support Plans 
Technology Refresh/Install Programs 



At DMD Systems Recovery, we remove the headache from asset 
disposal. We can manage the whole process from deinstallation to 
asset remarketing. W/e worry about data destruction, EPA 
regulations, logistics, and insurance so that you don't have too. 
Don't tie up your resources or take chances with you data or 
environmental issues. Call DMD today. 



f 



DMD SYSTEMS RECOVERY, iNC, 

lII Fma: i|Hr7^7I7-DHI Phone; [IB?] 3074 tSD F,gi: (ad?>3«iT-ltiai 
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Description 



Contact 




Description 



Contact 



able Suppliers 



ADC 





Black Box 



Founded in 1935 in IVIinneapolis, ADC has grown Into a leading provider of Innovative 
network infrastructure equipment and professional services, Including high-speed 
Internet, video, data, and voice to residential, business, and mobile subscribers on a 
global scale. With about 9,500 employees worldwide and sales in more than 130 coun- 
tries in Asia, Europe, Africa, and the Middle East, ADC provides connections for wired, 
wireless, cable, broadcast, and enterprise networks. 

ADC believes that the need for ubiquitous access, scalable bandwidth, and robust, 
reliable connectivity is no different whether the customer is a carrier, cable company, 
or enterprise, as all rely on ADC's network infrastructure expertise to help design and 
deploy broadband networks that deliver advanced but varying services to meet increas- 
ing bandwidth demand. 

Products include: 

• Fiber optic compact building plenum and riser cable 

• Augmented CAT 6 DTP plenum and riser data cable 

• Augmented CAT 6 F/UTP plenum and riser data cable 

• CAT 6 DTP plenum and riser data cable 

• CAT 5e DTP plenum and riser data cable 

Best For: All types of data center and enterprise applications — specifically, high-density 
situations where ADC's reduced-size copper cabling is an ideal fit. 



(800) 366-3889 
www.adc.com 



NetCablesPlus 



(netcaplespius 



Operating as an online network and PC cabling superstore, NetCablesPlus serves com- 
panies of all sizes that need high-quality cables, tools, and accessories at wholesale 
prices. Based in Cumberland, R.I., NetCablesPlus has been in the retail business since 
2004 and now has more than 20,000 customers. The company offers data center man- 
agers, systems integrators, and other business clients 24/7 online access to an invento- 
ry of more than 1 1 ,000 products from well-known manufacturers at low prices. 

All NetCablesPlus' cables are factory-tested and are sold with a lifetime warranty and 
unconditional money-back guarantee. Whether purchasing a single patch cable or a 
truckload of bulk reels of cabling, the company offers fast, friendly customer service that 
includes same-day stateside and offshore shipping. Most cable products can be shipped 
from facilities on the East Coast, Midwest, or West Coast to ensure fast delivery times 
and low shipping costs. 

Products include: 

• CAT 5e and CAT 6 patch cables 

• Fiber optic patch cables, including single-mode, multimode, and multiple 
connector types 

• Patch panels, keystone jacks, plugs, and adapters 

• Bulk cabling, tools, and accessories 

Best For: Data centers of any size requiring copper or fiber optic Ethernet patch cables. 



s» BLACK 

NETWORK SERVICES 



With 175,000 clients in more than 140 countries and 193 offices globally. Black Box 
is a major supplier of structured cabling, including end-to-end solutions for CAT 5e, 
CAT 6, CAT 6Aa, CAT 7, fiber, and custom cabling needs. In 1976, the company 
began offering free technical support before and after the sale for its networking and 
data communications products. Today, Black Box boasts 24/7, live, U.S. -based tech 
support with calls and clicks answered in 20 seconds or less. 

Most Black Box cables carry a guaranteed-for-life warranty as well as a best price guar- 
antee. Further, 95% of all Black Box's in-stock products ship the same day. The compa- 
ny also features hard-to-find legacy and custom products among its more than 1 1 8,000 
products that range in functionality to cover everything from the desktop to data center. 
Customers will also find a custom Cable And Adapter Configurator at the company's 
Web site. 

Products include: 

• Solid, stranded, high-density, harsh environment, and multiple color and length 
copper UTP and STP bulk and patch cables 

• Distribution, break-out, armored, indoor/outdoor, loose-tube, tight-buffered, and 
other fiber optic bulk and patch cables 

• Adapters, terminators, connectors, and data communications cables, including A/V, 
USB, and power cords 

Best For: Companies in need of any cabling solutions, from the desktop to the data center. 

(724) 746-5500 
www.blackbox.com 



PDU 
Cables 




Since 1 981 , PDU Cables has been a leading supplier of power distribution cable assem- 
blies to data centers throughout North America. The company's philosophy is to provide 
thorough product knowledge and quick customer service to data centers. In addition to 
being the first independent cable assembly company to introduce colored conduit into 
the power distribution market, PDU Cables was the first to get a UL 478 listing and to 
introduce the Power Cables and Equipment Configurator. The company is also the only 
supplier of the Air Guard Cable Seal product line. 

Based in Minneapolis, PDU Cables provides customers 24-hour turnaround and stan- 
dard transit times of one to three days to most U.S. destinations, although cable expedit- 
ing is available. Currently, more than 5,000 U.S. data centers use PDU Cables' products 
to save time and labor and help reduce overall project costs. 

Products include: 

• UL-listed and tested under-floor power cables 

• Molded cord assemblies 

Best For: Data center and facilities managers, electrical contractors, and raised-floor 
data center applications. 



(401) 475-6040 
www.netcablesplus.com 



(866) 631-4238 
www.pducables.com 
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Processots Product Spotlight highlights options available in key data center product categories, providing product information side-by-side for easy comparison. 

Compiled by Blaine Flamig 



Blue Wave Communications 





Blue Wave Communications says it is more Vnan just a cabling contractor that in- 
stalls structured cabling systems. Instead, the company sees itself as a "long-term 
partner committed to the highest-quality work with your best interest in mind." Op- 
erating from its Miami home base, Blue Wave Communications got its start in 2004 
as an extension of Compuquip Technologies, which had been in the cabling busi- 
ness for about 20 years before consumer growth warranted the launch of Blue Wave 
Communications to satisfy increasing demand for speed, efficiency, and security in 
cable infrastructure. 

Blue Wave initially performs a comprehensive onsite analysis of all network cabling 
needs for customers, after which the company is typically able to provide a customer 
quote within 48 to 72 hours. Following the installation of cabling systems, during which 
Blue Wave uses only in-house technicians and involves no subcontracted labor, the 
company completely tests and certifies the entire installed cabling system. Additionally, 
the company offers a one-year workmanship warranty and extended manufacturer war- 
ranties that range from 15 to 25 years. 



Products include: 

• CAT 5e and CAT 6 cabling 

• Existing infrastructure evaluation 



Optical fiber and CATV installations 
New cabling infrastructure 



Best For: Companies and organizations needing a contractor for structured cabling design 
and installation on large projects or everyday cabling moves, additions, and changes. 



(305) 436-8886 
www.bwcfla.com 



CableOrganizer.com 



i3 cableorganizer' 

com 



Co-founded in a garage by a husband-and-wife team with just $30 to register a Web site 
name, CableOrganizer.com has since grown into a global vendor of cable and wire 
management products. Based in Fort Lauderdale, Fla., CableOrganizer.com now oper- 
ates a subsidiary in Rennes, France, and boasts an inventory of more than 31 ,000 
SKUs available through the company's online storefront, which is aimed at everyone 
from individuals to large corporations, hospitals, and government offices. 

CableOrganizer.com's cable and related products are adaptable for home theater, com- 
puting, automotive, industrial, office, networking, and home settings. The company also 
claims several major global brands and organizations as customers. Customer sen/ice 
is available via phone, email, or the company's extensive online help center. Shipping 
for receipt usually occurs within two business days. 

Products include: 

• Fiber optic cabling 

• CAT 5e and CAT 6 cabling 

• Related tools, jacks, racks, ducts, and testers 

Best For: Anyone from individuals to large enterprises seeking a 24/7, one-stop 
shopping experience personalized to respective customers. 



(866) 222-0030 
www.cableorganizer.com 



Rackmount 
Solutions 




Rackmount Solutions has been in business since 2001 and is focused on providing 
rackmount storage solutions that make an IT/network professional's life easier. 
Where else can you get a series of Air Conditioned, Soundproof, Seismic, Shock- 
mount, and Co-Location Racks as well as 144 sizes of Standard Racks from one com- 
pany? All made in the United States. All with multiple configurations of doors, tops, 
fans, bottoms, rack accessories, etc. 



Wareliouse Cables 



Warehouse 
Cables 



Founded in 2002 and operating out of Warwick, R.I., Warehouse Cables is a national 
supplier of computer network cabling and connectivity-related products aimed at com- 
mercial, industrial, and military purposes. Selling aggressively priced standard, custom, 
and OEM cable products manufactured stateside and overseas, Warehouse Cables 
aims to optimize cable performance and ensure industry specification compliance for 
each cable by using quality components and cutting-edge construction technologies. 



You receive unparalleled customer service from staff who know the nuances of 
their products and can assist you in making your "best fit" decision. Order from the 
extensive 24/7 online e-commerce store or call the toll-free line to speak directly with 
a sales representative. 

Rackmount's ISO 9001:2008 quality managed system ensures government, commer- 
cial, educational, and reseller customers get on-time deliveries, fewer damaged ship- 
ments, and prompt responses to questions and returns. 

Products include: 

• More than 1 99 styles and sizes of enclosed cabinets 

• More than 1 52 sizes of open 4- and 6-post racks 

• Shielded and unshielded cable, stranded, solid, plenum, and fiber 

Best For: New or retrofit installations in data centers of all sizes. 



Through its Web site. Warehouse Cables operates with the goal of making it easy 
for customers to find what they need, letting customers locate, specify, and fill 
requirements in a few mouse clicks — an approach well-suited for companies that 
want the most direct means possible for purchasing. As a brick-and-mortar company. 
Warehouse Cables emphasizes strong customer support to help customers make 
informed purchases, completes credit approval quickly, meets high-volume require- 
ments, and provides pricing and delivery alternatives. In addition to same-day ship- 
ping. Warehouse Cables includes shipment notifications and tracking. 



Products include: 

• 568B category cable 

• Telephone cable 

• Audio/video cables 



Fiber optic cable 
Computer peripheral cables 



Best For: Companies seeking standard, custom, and OEM cable via an easy-to-use 
online setting. 



(866) 207-6631 
www.rackmountsolutions.net 



(866) 738-8993 
www.warehousecables.com 



Page 16 



Processor.com 



January 15, 2010 



PHYSICAL INFRASTRUCTURE PRODUCT SPOTLIGHT 



Three-Phase Power Distribution Units 



Cyber Switching ePower 
Product Family 




Cyber Switching's new ePower family is targeted at data 
center managers searcliing for greener solutions that inte- 
grate rich features while providing high reliability and great 
value. Patented Individual Outlet Metering provides billing- 
grade metering for each outlet at an accuracy of 2% or bet- 
ter. Utilizing the unit's full-color LCD touchscreen or a stan- 
dard Web browser, IT personnel can stay up-to-date on 
critical information, including real-time power information, 
load details, input line utilization, and system status. 

• Patented Cyber Breaker® technology protects equip- 
ment by limiting overcurrent conditions to a single outlet 

• Color LCD touchscreen for local management and setup 

• Two high-speed USB ports support up to 1 27 peripherals 

• 60+ high-density PDU configurations 

• Network connection for remote monitoring and man- 
agement of your power usage 

Best For: Companies looking to implement a compre- 
hensive data center management plan. 

(888) 311-6277 
www.cyberswitching.com 



Cyber Switching Galaxy Series Eaton 9395 UPS 




The Galaxy Series from Cyber Switching easily and 
affordably distributes single-phase or three-phase 
power within a three-phase infrastructure. Galaxy 
products are available in many different models and 
outlet configurations suited to fit customers' needs. 
The 660L, the 660L (2U), and the 6601 (2U) provide IT 
and facilities personnel with a flexible and cost-effec- 
tive tool for managing a three-phase infrastructure. 

• 20-, 30-, or 50-amp rated 

• Single or dual input cords 

• Two-pole circuit breaker protection 

• Standard 1 9-inch rackmount format (1 RU or 2RU 
depending on model) 

Best For: Organizations looking for a flexible and 
cost-effective PDU for managing their three-phase 
infrastructure. 



(888)311-6277 
www.cyberswitching.com 




Powering Business Worldwide 



Designed to offer a high level of power performance, relia- 
bility, and energy savings, the Eaton 9395 UPS provides 
backup power and scalable battery runtimes in a small 
footprint for large data centers, healthcare applications, 
and other critical systems and is available with power 
ratings of 225 to I.IOOkVA. 

• Provides stronger power performance with double-conver- 
sion design and Eaton's exclusive Easy Capacity Test 

• Offers high reliability and availability with Powerware Hot 
Sync paralleling, battery management, inherent redun- 
dancy, and a scalable architecture that adapts to increas- 
ing power requirements 

• Offers manageability with control and connectivity and a 
superior service offering 

• Delivers 99% efficiency without sacrificing reliability using 
Energy Saver System 

Best For: Companies that value data processing, storage, 
and power protection. 



(800) 356-5794 
powerquality.eaton.com 



Emerson Liebert NX UPS PDUs Direct C-21VY-L2120 
With Softscale Technology 



EMERSON 

Met work Power 



The Liebert NX UPS with Softscale technology 
is a true online, double-conversion three-phase 
UPS system that provides a scalable solution 
for growing data centers. The UPS allows 
growth from 40 to 60 to 80kVA and from 80 to 
100 to 120kVA. The UPS may also be paral- 
leled for additional capacity or for redundant 
operation. 

• Efficiency rating of up to 97% 

• Adaptable to current requirements and 
easily scaled with a software key as 
needs change 

• IVIodules can adapt from 40 to 60 to 80kVA 
or from 80 to 100 to 120kVA 

Best For: Small and medium-sized data cen- 
ters that are facing unpredictable changes in 
their IT systems. 



PDUs 



direct 



The C-21 VY-L2120 three-phase vertical PDU with amp 
meters offers the density support of three-phase power 
with the ability to load balance the phases using LED 
load meters. Additionally, it has 21 lEC CI 3 outlets, a 
locking three-phase NEIVIA L21-20P in-feed plug, and 
three integrated local amp meters (one for each phase). 
It also provides nearly twice (1 .732 times) the power 
density of a standard 208V circuit, and it can be mount- 
ed in the rear dead space so as to not eat up rack space. 

• Industrial-grade outlets and a steel case enclosure 

• High-quality powder coat 

• Three local LED phase meters with True RMS 
reading 

• Includes a hardwired power cord 

Best For: Small data centers that need overcurrent 
protection. 

Price: $310 



Raritan Dominion PX Intelligent Rack 
PDU Three-Phase Models 
PX-5532 & PX-5534 




Dominion PX intelligent PDUs measure power at the outlet level 
(RMS, apparent power), providing accurate views of power consump- 
tion at both a server and PDU level. They also provide detailed real- 
time power information, which is displayed conveniently at the power 
strip via an LED display and remotely through a Web browser. 
Raritan's three-phase Dominion PX models range from 208V to 400V 
models, including models that support both 120V and 208V in the 
same PDU. Each circuit is protected with a UL 489 circuit breaker. 

• Unit-level and outlet-level power utilization information 

• Finds problem hot spots and excessive cooling at the rack or 
circuit loads that are about to trip breakers 

• Controls outlet groups using a single IP address within a single 
PDU or across multiple PDUs 

• Alerts you via email, SMS (via external gateway), audio alarm, and 
SNMP TRAPS when a threshold is exceeded or a circuit breaker trips 

Best For: Companies looking for a solution that provides outlet-level 
information to efficiently manage data center energy, space, and 
productivity. 




Description 



Contact 




Contact 



(800) 543-2378 
www.liebert.com 



(888) 751-7387 
www.pdusdirect.com 



(732) 764-8886 
www.raritan.com 
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PRODUCT SPOTLIGHT 



HYSICAL INFRASTRUCTURE 



Processor's Product Spotlight highlights options available in key data center product categories, providing product information side-by-side for easy comparison. 

Compiled by Tessa Warner Breneman 



Eaton 9390 UPS 




The Eaton 9390 is a double-conversion UPS that resolves all utility power problems and 
supplies clean, continuous, uninterruptible power to connected equipment, and it is ideal 
for branch offices, manufacturing floors, medical facilities, or data centers. Its trans- 
former-less design offers increased efficiency over transformer-based UPSes. And with 
flexible installation, the 9390 can be mounted directly next to a wall or even in a corner, 
and it is completely accessible for service and maintenance from the front panel. 

• Voltage options include conventional 208V and 480V for standard U.S. system 
designs and 400V for higher-efficiency U.S. system designs 

• Advanced Battery IVIanagement offers cyclical battery charging and increases service 
life of batteries, which reduces total cost of ownership 

• Provides stronger power performance with optimum generator sizing, PFC power 
supply compatibility, and lowest THD (Total Harmonic Distortion), which enhances 
compatibility with upstream power systems 

• Delivers 99% efficiency without sacrificing reliability using Energy Saver System 

Best For: A data center with limited square footage. 



Emerson Liebert MPX 




The Liebert MPX is a three-phase rack PDU that provides hot-swappable power mod- 
ules and reconfigurable input power modules, allowing immediate onsite configuration 
of rack power to suit IT equipment needs. The system offers remote monitoring and 
control to the receptacle level and also monitors environmental input options such as 
rack temperature and humidity. A modular communications card allows a variety of 
monitoring options. 



• Flexible, comprehensive remote management 

• Onsite configuration of power input and distribution 

• Ability to reconfigure rack PDU input power from 20 to 60 amps 

• Receptacle modules can be switched out easily when power requirements change 

Best For: Companies that are expanding and modifying their data centers quickly. 



(800) 356-5794 
powerquality.eaton.com 



(800) 543-2378 
www.liebert.com 



Server Technology Sentry Smart CDU CS-27VY 30 
Amp & CDU CS-1 8V5 60 Amp With C1 9 Outlets 



Server Technology 

Solutions for the Data Center Equipment Cabinet 



The CDU CS-27VY 30 Amp and CS-18V5 60 Amp with C1 9 Outlets from Server 
Technology's Smart CDU family offers both local and remote power monitoring and 
environmental monitoring through IP as well as high-density (single-power input feed) 
and high-power distribution. Using a Web browser, the network interfaces let users view 
power, temperature, and humidity levels as well as receive SNMP-based alarms and 
email alerts when the aforementioned conditions exceed defined thresholds. Server 
Technology also offers 415V units in its vast stable of three-phase products. 

• Branch circuit protection 

• Input current monitoring using the Digital True RMS current monitoring for precise 
readings in high-density computing environments 

• Temperature and humidity measurements available from two external 10-foot probes 

• Expansion Module links two power circuits together under one IP address 

Best For: Expanding data centers and remote management. 



Server Technology Sentry 
Smart CDU CS-36VD/Y 



The CS-36VDA' mixed outlet three-phase PDU, which is designed for high-density 
applications such as blade server clusters, provides local and remote power monitoring 
in addition to environmental monitoring via IP. You view power, temperature, and 
humidity levels through a Web browser and receive SNMP-based alarms or an email 
alert if conditions have exceeded specified thresholds. The CS-36VD/Y also offers 
branch current monitoring to avert overloads using LED digital displays on the CDU 
enclosure. These displays portray the input current of each branch circuit to ensure 
loads are properly balanced. 

• Branch circuit protection 

• Branch current monitoring using the Digital True RMS current monitoring for precise 
readings in high-density computing environments 

• Temperature and humidity measurements through two external 10-foot probes 

Best For: Expanding data centers and remote management. 



(800) 835-1515 
www.servertech.com 



(800) 835-1515 
www.servertech.com 
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NETWORKING & VPN PRODUCT SPOTLIGHT 



VPN & Remote Connectivity 



Product 


ANX OfficeScreen 
uonipieie 

&Businoss 


ANX PositivePRO 


Aruba Networks 600 
Branch Office 
Controller Series 

p P ^ 




A 1 K 1 X 1 

Aruba Networks 

DAP 0\A/P Domntci 

nAr-ZvVb nenlOie 

Access Point 

1 


Description 


This cloud-based, fully managed SaaS 


Hosted in a carrier-class data center, 


This all-in-one hardware solution series 


Compact and inexpensive, this 802.1 1 b/g 




solution provides VPN functionality for 


ANX's PositivePRO is a SaaS program 


isn't just about providing site-to-site VPN 


access point supports secure VPN 




secure site-to-site access. Enterprises 


that gives geographically dispersed users 


connectivity in an edge device. The 600 


access to the corporate network. It can 




with far-flung employees and/or partners 


a safe means of accessing the corporate 


Series is simple to install and comes at a 


support enough users to make it more 




with network access requirements can 


network. Easy to use, the service supports 


modest price, making it ideal for home 




than adequate for home office, telecom- 




benefit from OfficeScreen Complete's 


group-based policy management of 


office and telecommuter use as well as 


muting, clinic, and kiosk scenarios. 




continually updated protection. 


access rights for various clusters of users. 


for sen/ice in clinics and branch offices. 














• Dual LAN ports 




• Provides security for access points 


• Constantly monitored 


• Supports Wi-Fi (with a dual-band 




• Suitable for concurrent use with VoIP 




• Includes a firewall 


• Performs endpoint security 


802.1 InAP in the 651 model) 




phones and other devices 




• Offers failover support 


assessments and dynamic 


• Includes file and print sen/ers 




• Budget priced 




• Can perform traffic shaping 


authentication in real time 


• Supports Power over Ethernet-t- and 


• Small footprint 




• Helps with compliance to PCI DSS, 


• Support personnel are available via 


IGbps LAN 








Sarbanes-Oxley, GLBA, and HIPAA 


live chat 


• Comes with a built-in firewall 




Best For: One- to five-user sites, kiosks, 
SOHO users, and telecommuters. 




Best For: Organizations with remote 


Best For: Enterprises focused on 


Best For: Branch offices with multiple 








user security and regulatory compliance 


compliance and internal and external 


users. 








needs. 


access security. 








Contact 


(877) 488-8269 


(877) 488-8269 


(408) 227-4500 




(408) 227-4500 




www.anx.com 


www.anx.com 


www.arubanetworks.com 




www.arubanetworks.com 














Product] 


D-Link DFL-2560G 


Juniper Networks SA 


SafeNet HighAssurance 


SonicWALLAventail 


HI 


Motnofonrl 1 IT^/I 

Nciueiena u i ivi 


9c;nn qqi \/pm 


4000 (v5) Gateway 




F Place PY IRf) 
t-UiaSS LA-/ jU 


I 


Firewall 


Appliance 

^ ^^^^^ 








■ 










50NKWALL> 


Description 


Similar in most respects to the D-Link 


Juniper's SA 2500 SSL VPN Appliance 


Dubbed HA4000 (v5) for short, this 




This VPN eschews IPsec in favor of SSL. 




DFL-2560 (albeit not in price), this vari- 


can support up to 100 concurrent users 


gateway appliance handles most VPN 




It's designed to be simpler to use, less 




ant differs most noticeably in its LAN port 


and features dual Gigabit ports. The SA 


needs. It lets organizations safely and 




expensive to operate, and less likely to 




configuration. Its SFP ports can be used 


line is extremely scalable (also shown are 


securely take advantage of the lower 




generate calls to tech support. The 




with fiber connections for flexibility. 


the SA 4500 and SA 6500). 


costs of communication over the Web 




secure remote access device gives even 
small offices enterprise-class security. 




• Six Gigabit jacks 


• Audited by iSEC Partners and 


• Ready to protect remote and site-to 








• Four small form-factor pluggable 


Cybertrust 


site access 




• Endpoint control interrogation at con- 




uplink ports 


• Suitable for mobile devices, terminal 
services, Web app availability, and 


• Comes with SafeNet's Security 
Management Center SNMP 




figurable intervals and/or login 
• Access control by user, group, IP 




Best For: Applications with fiber uplink 


client/server connections 


monitoring and administration software 


addresses or range, and much more 




requirements in medium-sized to large 


• Provisioning by purpose support: 






• Clientless system 


1 


enterprises. 


SAM, NC, and clientless core Web 
access 

Best For: Any company or service 
provider with complex and demanding 
security requirements. 


Best For: Government agencies, 
financial institutions, and cloud 
computing and managed service 
providers. 




• Can handle mobile connections and 
other endpoint device platforms 

Best For: Enterprise departments, 
remote offices, and SMEs with up to 50 
concurrent users. 


Contact 


(714) 885-6000 


(888) 586-4737 


(800) 533-3958 




(888) 557-6642 




www.dlink.com 


www.juniper.net 


www.safenet-inc.com 




www.sonicwall.com 
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Processor's Product Spotlight highlights options available in key data center product categories, providing product information side-by-side for easy comparison. 

Compiled by Marty Sems 



Aruba 




Black Box 


D-Link DFL-1660 


D-Link DFL-2560 


Networks 




FireTunnel 30 


NetDefend UTM 


NetDefend UTM 


RAP-5 






Internet Security 


Firewall 


Remote 






Appliance 




Access 


ARUBA ■ 








Point 


i< 

t 






i ^ 










w 1 


The RAP-5 family comes with 


FireTunnel 30 from Black Box is a complete stateful 


D-Link's unified threat management 


Compared to the DFL-1660, the 


enhanced capabilities compared 


inspection firewall that offers enterprise-class fea- 


products combine VPN support 


DFL-2560 is a faster VPN device with 


to the RAP-2WG. These Virtual 


tures for less than $350. Because it's virtually plug- 


with Kaspersky anti-malware, intru- 


the ability to handle more IPsec tunnels, 


Branch Network products are sim- 


and-play, it's an ideal solution for organizations 


sion prevention, and more. The 


and it has more Gigabit ports. This 


ple to install, Aruba says, and can 


1 without a dedicated IT staff. 


DFL-1660 in particular provides up 


NetDefend can ferry up to 2Gbps of 


satisfy even advanced remote 




to 350IVIbps of VPN access speed 


firewalled traffic, too, in contrast with its 


users. 




• Full stateful inspection firewall 


with hardware-based 3DES or AES 


little brother's 1.2Gbps capabilities. 






1 • Supports up to 30 VPN tunnels for secure 


encryption and can handle up to 




• Hardware-accelerated encryption 


remote data access 


2,500 IPsec tunnels. 


• 1 Gbps VPN throughput with 3DES or 


comes standard 




• Can act as a VPN concentrator, enabling multi- 




AES encryption 


• Supports 3G cellular modems via 


ple remote users to securely connect to each 


• Web content filtering 


• Supports up to 5,000 IPsec VPN 


USB 




other through a FireTunnel in the home office 


• Dual-core processing 


tunnels 


• Five Ethernet ports 


• Load balancing across two WAN connections — a 


• 1 U rackmount form factor 


• 10 Gigabit ports 


• Optional 802. 1 1 n support 


feature usually seen only on expensive, enterprise- 


• Six configurable Gigabit Ethernet 


• Fits in a 1 U rack space 






class firewalls 


ports 








• Incorporates an 8-port switch and router to 




Best For: Medium-sized to large 


Best For: SOHOs and branch 


make it a true all-in-one Internet appliance 


Best For: Small to medium-sized 


enterprises. 


offices with multiple users. 




enterprises. 








Best For: Small to medium-sized organizations 










with high security requirements and tight budgets. 






(408) 227-4500 




(724) 746-5500 


(714) 885-6000 


(714) 885-6000 


www.arubanetworks.com 


www.blackbox.com/goA/PN 


www.dlink.com 


www.dlink.com 



SonicWALLAventail 


SonicWALLAventail 


StoneSoft StoneGate 


StoneSoft StoneGate 


E-Class EX6000 


E-Class EX7000 


FW-310 Firewall/VPN 


FW-5105 Firewall/VPN 






STONESOFT 


STONESOFT 


Building on the capabilities of the 


In addition to its significantly higher 


Network complexity is just as big a 


Boasting a 25Gbps firewall and 5Gbps 


Aventail EX-750, the EX-6000 steps up 


connection capacity, the EX-7000 


security problem as malware and 


VPN throughput, the FW-5105 provides 


to the plate with the ability to handle up 


diverges from SonicWALL's other 


hackers, says Pentti Lehtinen, Stone- 


relatively fast, secure remote access. Its 


to 250 remote connections. Still, it pro- 


Aventail E-Class SRAs, coming standard 


soft's technical director for the Americas. 


StoneGate Management Center offers 


vides the same ease of use and remote 


with features that are optional on the 


The more complex the system, the less 


single-console control of all parts of your 


access security characteristics as its 


lesser systems. 


likely it will be properly secured. To that 


organization's network. 


smaller sibling. 




end, StoneGate sells VPN and firewall 






• Supports eight times as many connec- 


devices such as the 250Mbps FW-310 


• Multi-Link feature supports connec- 


• Flexible EPC interrogation settings 


tions as the EX-6000 


that play multiple roles. 


tions of multiple types 


• Workplace Mobile feature to support 


• Built-in anti-malware and firewall 




• Allows throughput enhancement 


phone browser access 


protection 


• Offers load balancing 


• Helps avert temporary outages, 


• Multi-OS access to UDP and TCP 


• Supports Windows Mobile 


• Replaces backup connections 


including those for maintenance 


applications 


• Provides native access modules for 


• Simplifies management of third-party 


• Four 1 0Gbps fiber ports, 1 8 1 Gbps 




Windows Terminal Services and Citrix 


devices 


ports 


Best For: Medium-sized organizations 




• Improves overall network connectivity 




with 25 to 250 simultaneous users. 


Best For: Enterprises with 50 to 2,000 


and performance 


Best For: Medium-sized to large 




remote users. 




enterprises. 






Best For: Medium-sized to large 








enterprises. 




(888) 557-6642 


(888) 557-6642 


(866) 869-4075 


(866) 869-4075 


www.sonicwall.com 


www.sonicwall.com 


www.stonesoft.com 


www.stonesoft.com 
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3G & The Enterprise 



What Could Third-Generation Connectivity IVIean For Your SIVIE? 



by Elizabeth Millard 

In terms of buzz, 3G is certainly enjoy- 
ing its time in the spotlight. As defined by 
the International Telecommunications 
Union (www.itu.int), 3G is a family of 
standards that boosts the capability of a 
mobile environment, and as cell providers 
have learned, it's already all the rage 
among consumers. 

Although 3G has been around since 
2001, it's been plagued with issues such as 
spectrum licensing fees in some countries 
and network build-outs by mobile opera- 
tors. In the past few years, though, it's 
gained much more traction worldwide, 
and telecoms have been working to roll 
out the tech to more cities and expand 3G 
coverage as quickly as possible. 

Now that the early adopters have their 
devices and 3G is ready for the next con- 
sumer wave, it shouldn't be long before 
enterprises will see increased demand 
among employees, as well. Like all tech- 
nologies, 3G has its benefits and disadvan- 
tages as well as limitations. 

Advantages & Drawbacks 

As with other mobile advances, the 
main stumbling block for 3G right now is 
coverage. Not all cities, suburbs, and rural 
areas have 3G, and although this might not 



The advantages, though, can be formi- 
dable. The technology offers faster data 
speed when using the mobile phone as a 
modem, connecting a PC to the Internet 
via the phone. Also, many experts have 
noted that there's better performance with 
the mobile Internet, so users can browse 
the Internet or access information faster. 
There tends to be a higher speech quality 
on the edge of network coverage area, as 
well, and if the phone supports video call 
capabilities, they're usually sharper and 
more seamless. 

One major benefit is in security; 3G 
networks boast a higher degree of security 
than predecessors, because 3G net- 
works use the KASUMI block crypto, 
designed by the Security Algorithms 
Group of Experts. 

Get Detailed 

"An important matter is not to think of 
the overall 3G technology first; it's actual- 
ly the reverse," says Vesa Kiviranta, busi- 
ness development director at Elektrobit 
(www.elektrobit.com), a developer of 
automotive and wireless technologies. 
"One needs to look at the applications 
used, because they are what will drive the 
possible need for 3G." 

He adds that more "data-savvy applica- 
tions" have better usability with 3G. 



3G technology offers faster data speed 
when using the mobile phone as a 
modem, connecting a PC to the 
Internet via the phone. 



be important for some consumers who 
stick close to the same city most of the 
time, it can be a disadvantage for a mobile 
employee who has to tap into the company 
network and get mobile services from any- 
where. Also, costs for 3G devices tend to 
be higher than for 2G or 2.5G devices, so 
an IT department would have to consider 
whether switching makes sense from a 
budget standpoint. 



Because of its bandwidth capabilities and 
better ability to pinpoint 3G devices, the 
technology is driving applications in a 
number of industries (see the "Application 
Advantage" sidebar). 

Kiviranta advises companies to examine 
whether the types of 3G applications 
available would be advantageous. For 
example, videoconferencing on 3G phones 
is likely to be a major selling point, so 



Key Points 



• Instead of thinking about 3G teclinology 
overall, focus instead on what types of 
applications are available and make 
sense for your enterprise. 

• 3G's main advantages are quicker data 
speed, better performance, and higher 
speech quality, but it may not cover all 
areas just yet. 

• Consider 3G when a better data rate is 
needed, particularly for synchronizing 
PIM information. 



SMEs that have a large number of mobile 
employees may want to switch to 3G to 
tap into this capability. 

Looking Toward Implementation 

After considering the types of applica- 
tions that are available and noting the 
advantages of 3G — if coverage is ade- 
quate — the next step for an SME would be 
to examine whether the technology would 
fit well within an existing environment. 

For some companies that have a consid- 
erable number of mobile devices, it might 
be worth waiting to switch to 3G until 
mobile contracts near expiration. Al- 
ternatively, many carriers offer upgrade 
services, so having a conversation with a 
mobile provider can be useful. An IT 
manager might even be able to negotiate 
buying new devices in bulk and having the 
vendor provide some training materials 
or support. 



Another factor is consideration of 
how 3G might fit into a current unified 
communications strategy. If such a sys- 
tem is in place, it's important to analyze 
usage, including how employees work 
and interact with each other and cus- 
tomers, says Chris Rafter, vice president 
of consulting services at Logicalis 
(www.us.logicalis.com), a provider of 
integrated information and communica- 
tions technology solutions. 

When dealing with implementation, 
either of a unified communications 
strategy, 3G, or any other aspect of 
communications technology. Rafter 
advises working in stages: "Give people 
time to get used to each new technolo- 
gy," he says. "It builds anticipation, and 
people like getting something 'new' 
every two or three months. Also, test and 
pilot thoroughly and make sure every- 
thing works." 

In some cases, an enterprise might find 
that 3G doesn't work for them quite yet. 
For example, Kiviranta points out, 3G 
doesn't bring any advantages if used for 
voice-only communications, so if sales 
reps are only making calls and not access- 
ing email or synchronizing information, 
the upgrade would be a waste of money 
and effort. 

But for companies that want to signifi- 
cantly boost their capabilities with mobile 
email and mobile Internet, as well as 
increase the ability to synchronize PIM 
information over the air, 3G is likely to be 
well received. After all, who can resist a 
faster, sleeker, fun new gadget? 



Application Advantage 

Here's a glimpse at some of the capabilities for 3G device users that they haven't had with 
previous iterations: 

• Real-time videoconferencing, similar to videoconferencing on desktop computers, but 
now available on a device. 

• Video-On-Demand, where a provider can send a movie to a subscriber's phone, or a 
sales rep might send a corporate video to a client, for example. 

• Tele-medicine, in which a medical provider can monitor or diagnose a patient who's in 
another location. 
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SIX QUICK TIPS 



When Networks Collide 

Bringing Together Two Different Networks Is Easier Than It Used To Be 



by Drew Robb 

There are many reasons why networks 
collide. A merger, for example, brings two 
disparate networks under one umbrella. 
Technology evolution, too, can lead to one 
part of the company being on a more 
sophisticated networking technology than 
another. And, of course, the continuing 
trend of convergence has brought together 
voice and data in the form of VoIP as well 
as the combination of storage (Fibre 
Channel) and regular Ethernet-based net- 
working known as FCoE (Fibre Channel 
over Ethernet). For those left in the middle 
of these networking collisions, however, 
it's not always easy to bring everything 
together. So where do you start? 

Bring Physical Cabling Up To 
At Least 1Gbps 

Ethernet is the main networking technol- 
ogy used today. However, when networks 
come together, you typically find some 
parts running slower than others. Why? 
Many SMEs make a habit of curtailing 
bandwidth at the user level, or else only 

Smart Tip: 

Keep Users Informed 

It is wise to always keep users informed 
about what is happening during a networl<- 
ing integration. If applications or services 
will be down at all, let them know which 
ones and when. This can reduce anger 
among staff, as they won't be caught off 
guard. And if new applications and services 
are to be added, offer plenty of education in 
advance so they buy in on the reasons for 
network upgrades. 

"Informing users has an impact on user 
receptiveness to change as well as the inte- 
gration timeline," says Stephen Brown, a 
product marketing manager at Network 
Instruments (www.netinst.com). 

Best Return On Investment: 

Storage Convergence 

storage and networking used to be galax- 
ies apart. Now they often live in the same 
house. Storage's FC and networking's 
Ethernet can now live together using FCoE. 

"Organizations no longer have to run parallel 
infrastructures to support a Fibre Channel 
SAN and a local-area network," says Kash 
Shaikh, product manager for Data Center 
Solutions at Cisco Systems (www.cisco 
.com). "You no longer require separate 
cabling, switches, host bus adapters, and 
network interface cards." 

The cost of all those networking appendages 
can quickly add up. And with 10Gb Ethernet 
available, FCoE can greatly reduce the 
amount of sen/er adapters and cables need- 
ed in the data center. It also enables the 
convergence of Fibre Channel storage, IP- 
based storage such as iSCSI or NAS, and 
the LAN. 



upgrading the data center and leaving 
office spaces running at a slower pace. 

If you have an older office, you may be 
shocked to find a few areas still running on 
ancient 10Mbps Ethernet lines. A more 
likely scenario, though, is to find some 
offices or parts of the network still using 
100Mbps while the data center runs at 
IGbps or higher. 

"IGbps is probably the standard for 
many SMEs," says Sabine Waterkamp, 
president of outsourced IT services pro- 
vider ACSLA (www.acsla.com). "You can 
speed things up nicely by throwing out any- 
thing that is below 1Gb per second." 

Eradicate Hubs 

Ten years ago, everyone was using hubs. 
Now they are virtually obsolete. But you 
still find them in various nooks and crannies 
of the network. A hub takes one cable and 
splits it into several other cables. Everyone 
on the hub suffers a phenomenon known as 
collision: When a PC sends a signal, it goes 
to all the other stations joined to that hub. 
This is similar to an old problem with DSL. 
When everyone on the street was online at 
the same time, there would be a noticeable 
performance degradation. 

A switch, on the other hand, works quite 
differently. It receives a signal and repeats 
it, which means that no one else hears that 
signal. What can happen, then, is a slick 
hubless network gets joined together with 
an older network weighed down with 
aging hubs. 

"Switches allow one-on-one connection 
between the user and the switch, while 
hubs put all the connections into one big 
pot," Waterkamp says. "Hubs were pre- 
ferred in the past because of the cost. 
Switches have come down a lot since then. 
If you still have hubs, migrate to switches." 

Look At The Bigger Picture 

When two companies merge, it is impor- 
tant to realize that two IT teams and two, 
often different, networks are also merging. 
This can lead to internal arguments among 
staffs. The people involved will likely dis- 
agree on what's best based on what they 
are used to. 

"Before you begin to integrate any net- 
works, you'll want to look at the cultures 
of IT teams, approaches to network man- 
agement, and other related issues," says 
Stephen Brown, a product marketing 
manager at Network Instruments (www 
.netinst.com). 

Company cultures, after all, are affected 
by everything from management styles to 
industry and even company size. Disparate 
cultures working together can lead to fric- 
tion and act as a barrier when trying to 
merge the networks. 

Windows and Linux users, for instance, 
are often quite different camps. 

"When you merge a predominantly 
Windows-based network with a Linux net- 
work, you'll have to be careful how you do 
this," Brown says. "Do you migrate one OS 
to the other?" 

If most users are on Windows, it's safest 
to go with that. But make sure you take 
steps to appease any complaints from the 
Linux side. If cost cutting requires a move 
to Linux, be sure to educate Windows users 
on the new OS. 



Pay Careful Attention To Applications 

Applications are the lifeblood of orga- 
nizations. Any changes to the network 
can exert a serious impact on applica- 
tions. Map out the key applications and 
services for the merger and discuss which 
are the most efficient to maintain and 
which redundant apps to eliminate to 
cut costs. 

In addition, merging networks is a good 
time to look at different options for appli- 
cations. Rather than using a self-hosted 



BONUS TIPS 



■ Assess security before networks are 
brought together. It is vital to assess security 
to ensure neither network puts the other at risk. 
If one is vulnerable, it can open up back doors 
to the other. 

"When you bring networks together, you have 
to review security methodically," says Sabine 
Waterkamp, president of outsourced IT ser- 
vices provider ACSLA (www.acsla.com). "The 
other side may be wide-open, so you have to 
do a security assessment on that network to 
confirm you aren't at risk." 



application, it might be time to consider a 
cloud-based option. Clouds can save time 
and money, two things that are usually 
needed during a merger. 

"If two companies are already consider- 
ing merging two CRM databases, it would 
also be a good time to consider a cloud- 
based application," Brown says. "Such 
moves could save significant time and 
money by reducing demand for internal 
resources and the time network teams 
spend troubleshooting internally hosted 
applications." a 



■ Smarten up your switches. There are sever- 
al types of switches that might be around, espe- 
cially on older networks. Dumb switches get the 
signal across and little else. Level 1 and 2 switch- 
es allow more sophisticated actions, such as 
monitoring, with Level 2 having better overall 
security. Level 3 switches add a whole lot more, 
such as advanced routing capabilities, but they 
are a lot more expensive. Waterkamp suggests 
that any and all dumb switches be eliminated, as 
they can't be monitored by the network manage- 
ment system. Level 1 or 2 switches, though, are 
often good enough for most networks. 




Simple & Quick 
Baclcup & Recovery 

CMS Products BounceBacIc Ultimate 



by Seth Colaner 

Every data center employee knows 
the necessity of backup and recovery 
solutions. CMS Products' BounceBack 
Ultimate is designed to be a "digital 
spare tire" for PCs, allowing users to 
back up and restore the entire contents 
of a PC, including applications, data, 
personal settings, operating system, par- 
titioning, and formatting. 

Features include Instant PC Recovery, 
which lets users start up a PC from an 
external USB hard drive in case the 
operating system or hardware malfunc- 
tions, and instant One-Button Recovery, 
which is a simple and direct way of 
restoring a PC hard drive without the 
need for reinstalling anything. The 
QuickRestore function also lets users 
quickly restore specific files and folders. 

Other features include CDP (Contin- 
uous Data Protection), a function of 
BounceBack Ultimate that continuous- 
ly keeps new or modified files up-to- 
date; the ability to let Bounce-Back 
Ultimate run its processes in the back- 
ground so users can continue to work 
while the program takes care of busi- 
ness; and easy-to-configure AES 256- 
bit en-cryption to secure your data 
from prying eyes. 



BounceBack Ultimate also lets users 
back up to multiple media, such as an 
external hard drive or network drive, 
simultaneously so users can have multi- 
ple concurrent backups. With synchro- 
nization capabilities enabled, users can 
save a backup of their projects on a 
backup drive and use the drive on other 
computers. When the drive is again con- 
nected to the original computer, 
BounceBack Ultimate automatically 
syncs the changes, ensuring you're 
always working with the most up-to-date 
files. Users can also schedule backups 
and create backup sets. 




CMS Products 
BounceBack Ultimate 

Full download: $89 
Full CD: $99 
Upgrade download: $69 
Upgrade CD: $79 

Lets users back up and restore the 
entire contents of a PC. 

(800) 327-5773 

www.cmsproducts.com 
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Are You Ready 

For A Software Audit? 

Illegal Software Could Be Lurking On User Desktops 



by Drew Robb 

Few SMEs give much thought to the pos- 
sible presence of unlicensed software in 
their midst. Yet organizations such as the 
Business Software Alliance and the 
Software & Information Industry Asso- 
ciation carry out regular policing actions 
to detect illegal applications and OSes. 



His advice is to know what you have 
installed and licensed. 

"Organizations may not know they 
have a problem because they do not 
invest in effective software asset man- 
agement (SAM)," Beruk says. "SAM can 
help an organization to understand 
what they have installed and what they 
have licensed." 



The amount of time consumed can be 
minimized if organizations accurately 
gather up-to-date information about 
how their software products are being 
used, accessed, and permissioned. 



And these organizations often encourage 
whistleblowers to come forward. 

Michael Patterson, president of net- 
work monitoring vendor Plixer (www 
.plixer.com), has experienced this first- 
hand. In his case, a postcard from the 
BSA led to unwanted attention from a 
policing body. 

Liabilities Abound 

So what are the potential liabilities of 
unauthorized software? Peter Beruk, 
senior director of compliance marketing at 
the BSA, says unauthorized software 
comes with a host of risks for the organi- 
zation. It may have been tampered with, 
may not have been acquired from a legiti- 
mate source, or may be infected with mal- 
ware. In extreme cases, it can open the 
organization's network to unauthorized 
users. In addition to the security risks, 
there are also financial risks with unautho- 
rized software. U.S. copyright law allows 
for penalties of up to $150,000 per 
infringed title. 



Tools & Resources 

Many software vendors and the BSA 
offer tools and resources to help organi- 
zations know what they have installed 
and licensed. Audit tools, suggested poli- 
cies and procedures, and more are 
offered in order to assist organizations in 
effectively obtaining and maintaining 
license compliance. 

Just how bad of a problem is unautho- 
rized software? A recent IDC study on 
piracy found that the worldwide piracy 
rate is unbelievably high — an estimated 
41% of software on PCs is pirated. In the 
United States, however, that level is about 
20%. But with one in five organizations 
guilty of infringement, surprise audits are 
not likely to go away any time soon. 

"Organizations that can document tested 
procedures and show that periodic audits 
are regularly done are much less likely to 
be audited," Beruk says. "Even if they are, 
a recent audit report will go a long way to 
showing the entity requesting the audit 



that the organization takes the issue of 
compliance seriously." 

Avoid An Audit 

Like an IRS audit, you don't want to 
undergo a software licensing audit if you 
can avoid it. At Plixer, a business rival had 
a disgruntled employee contact the BSA 
about possible license violations. The 
BSA then demanded an audit, which dis- 
covered an illegal version of one program 
that was uninstalled. 

"The BSA was very reasonable about 
it — I sent them a spreadsheet showing 
what we had installed and what we 
owned," Patterson says. But the process 
took a considerable amount of time," 
he says. 

In other cases, an auditor might show up 
onsite unannounced in order to assess 
whether the organization is in compliance 
with the software licensing agreement. 
The safe approach is to verify compliance 
after every merger, expansion, reorganiza- 
tion, or system upgrade. 



Key Trends In 
Software Pricing 
& Licensing 



According to a survey conducted by 
Flexera Software (www.flexerasoft 
ware.com): 

61% of IT managers believe tracking 
software usage is important to reduce 
costs, minimize shelfware, and ensure 
compliance 

50% of respondents claim they are confi- 
dent they could successfully survive a 
software audit 

53% say some software license spend is 
associated with application overuse 



"These events can be a time and 
resource drain as already overburdened 
staff must scramble to manually reconcile 
license usage with license entitlements," 



Key Points 



Policing organizations are actively looking 
for companies using illegal applications 
and OSes. 

The penalties for licensing violations can 
be severe. 

The best solution is to automate the 
tracking of software licensing manage- 
ment and to always know what you 
have installed. 



says Jeff Greenwald, senior director of 
product management at Flexera Software 
(www.flexerasoftware.com), a software 
licensing management vendor. "This can 
be complicated by the fact that the 
licensed users are spread over many 
offices and systems." 

The amount of time consumed can be 
minimized if organizations accurately 
gather up-to-date information about how 
their software products are being used, 
accessed, and permissioned, as well as 
how their high-value software application 
deployments compare to their actual con- 
tracts. This is best done using an automat- 
ed software approach. 

"IT organizations that rely on manual, 
event-driven fire drills to true up their 
software licenses face disruption of 
normal IT operation, chronically incom- 
plete and inaccurate information, and 
exposure to license violations or license 
over-subscription," Greenwald says. "To 
avoid these consequences, IT organiza- 
tions should proactively implement 
proven software license management 
best practices, including the ongoing, 
automated monitoring of their deploy- 
ments in relation to their current licens- 
ing agreements." 
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FEATURED PRODUCT 

Monitoring Next-Generation 
Web Transactions 

AlertSite Lets IT Professionals See E-Commerce 
From The End User's Perspective 



* tin it (» i 



by Joseph Pasquini 

The Internet has revolutionized the way 
we all do business. Driven by consumer 
demands and a need to reduce operating 
overhead, many enterprises are shifting an 
increasing percentage of their 
potential revenue streams to an 
online sales presence. At the same 
time, evolving Web-based tech- 
nologies continue to be leveraged 
in an effort to attract shoppers and 
ultimately amplify sales revenue. 

Unfortunately, this increased 
reliance upon both new and 
maturing Web-based technologies 
also brings with it a level of peril. 
Just as 'brick and mortar' shop- 
pers will not tolerate unruly sales 
associates or bogus sales, online 
shoppers are not interested in 
poorly performing Web sites or 
cumbersome checkout transac- 
tions. As a result, e-commerce has 
become a high-stakes game of 
vast potential revenue and loss. 

To help gauge Web site uptime 
and performance from the cus- 
tomer's perspective, AlertSite (www. alert 
site.com) created its DejaClick transaction 
monitor utility, which captures and records 
the Web experience from the actual end 
user's perspective and provides developers 
with information about the performance of 
pages, links, components, and objects as 
well as common browsing activities. 

"Increasingly, for many organizations, 
online performance means business perfor- 
mance," says Ken Godskind, AlertSite's 
chief strategy officer. "Businesses are 
expanding their reUance on the Internet as a 
way to carry out more and more business 
functions or interact with customers. The 
success of those interactions, and thus the 
business, is dependent on delivering a quali- 
ty customer experience." 

Built Into The Browser 

Designed as a WYSIWYG add-on for 
Firefox, DejaClick lets users record any 
series of steps or actions they take within 
the browser and then play them back with 
just a single cUck. "DejaClick is a complete- 
ly 'built into the browser' Web application 
and performance monitoring solution," says 
Godskind. "Anyone can download it and 
use it as a macro or Super Bookmark utility 
and to generate scripts you later want to test 
for performance. It's fast and easy to use 
and requires no technical expertise." 

HAlertSite. 

Thanks to the new TrueScreen technolo- 
gy found in DejaClick 2.0, AlertSite's mon- 
itoring add-on now features the ability to 
interact with non-native browser applica- 
tions. As a result, users can record interac- 
tions on any embedded browser object, even 
if the browser itself can't see or hear any of 
the mouse clicks or keyboarding. The 
recording and replaying of scripts within 



varying operating systems is also supported. 
"In addition, DejaClick 2.0 automatically 
detects and adjusts for all the dynamic fea- 
tures of AJAX," says Godskind. 

According to Godskind, the new version 
of DejaClick also features powerful custom 
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DejaClick records and monitors Web site interaction 
from the end user's perspective. 



Java scripting capabilities, allowing the tool 
to execute JavaScript that is not directly part 
of a Web site being analyzed. DejaClick 2.0 
also includes AlertSite's proprietary True- 
User technology, which lets IT profession- 
als click buttons and links and enter data 
into fields just like a real end user would do. 
"The result is that such users can see all the 
performance details of the page, just like a 
real browser sees it," says Godskind. 

Godskind adds, "The new version allows 
you to replay activities even if the embed- 
ded object appears in full-screen mode or 
scrolls off the page; account for differences 
in replay speed, window size, object auto- 
sizing, or screen resolution; and translate all 
of this between the computer doing the 
recording and the one doing the replays." 

Additional Enhancements 

DejaClick' s DejaCapture feature provides 
a complete snapshot of the monitored Web 
site when an error or alert occurs and lets 
users capture the information pertaining to 
the event and drill down within the data to 
indentify root causes. The generated report 
includes information such as screen image, 
header information, and page source code. 

Designed to provide annotating capabili- 
ties, DejaNotes is a highly flexible feature 
of the DejaClick add-on. With DejaNotes, 
users can overlay messages onto DejaClick 
scripts; these notes appear onscreen for 
other DejaClick users to see whenever 
scripts are replayed. Such notes may contain 
comments, reminders, detailed instructions, 
hyperlinks, and videos. In addition, users 
may customize the size, shape, and place- 
ment of notes, and script playback can also 
be configured to pause, stop, or continue 
whenever notes appear. 

Differentiating Itself 
From The Competition 

Godskind contends that DejaClick 2.0 is 
unlike any other monitoring tool currently 



available. "Unlike other tools in the market, 
DejaClick is a 'what-you-see-is-what-you- 
get' experience," explains Godskind, who 
adds that turnaround time while using the 
add-on is dependent only on how fast one 
records a transaction. 

"DejaClick generates scripts 
automatically, in real time, by fol- 
lowing user click streams, as 
opposed to other tools on the mar- 
ket, which require users to stop 
and manually account for applica- 
tion think-time," says Godskind. 
"Additionally, there are no delays 
in monitoring to wait for scripts to 
go off to scripting or engineering." 

He continues, "Developing 
and testing the performance 
of complicated scripts and pro- 
cesses with other tools could take 
days and cost businesses thou- 
sands of dollars. With DejaClick, 
it is instantaneous. It's also 
incredibly easy to use and 
doesn't require high-level train- 
ing or skilled resources. Anyone, 
with or without technical exper- 
tise, can use it." 

It All Comes Down To Numbers 

Godskind is adamant in his belief that 
online consumers have increasingly high 
expectations regarding Web site respon- 
siveness. "In 2001, Zona Research released 



AlertSite DejaClick 2.0 

' (877)302-5378 
www.alertsite.com 

Description: Web application and perfor- 
mance monitoring solution intended for use 
I Willi Firefox browser. 

Interesting Fact: DejaClick automatically 
detects and adjusts for human think time, 
cookie-based form filling, differences between 
new and repeat users, network activity, third- 
party-generated content, and other dynamics 
associated with rich Internet applications. 



its '8-second rule,' a study which found 
that Web users will wait up to eight sec- 
onds for a page to download," says 
Godskind. "The length of that waiting peri- 
od has steadily decreased, dropping to 5.1 
seconds in 2008 (The Aberdeen Group), 
then to four seconds (NetForecast' s 
APDEX), and finally to a mere two sec- 
onds in 2009 (Forrester Consulting and 
Akamai Technologies)." 

"With statistics such as these, organiza- 
tions need to be sure their Web sites and 
applications — their interface with cus- 
tomers, suppliers, prospects, employees, and 
other constituents — are performing and 
responding well and offering users a high- 
quality experience at all times," says 
Godskind. "DejaClick captures exactly what 
users are seeing and experiencing, allowing 
business owners and IT leaders to make 
informed adjustments and decisions to 
enhance that experience." 




I iPhone Leads Pack 
Among U.S. Phone Usage 

Based on data gathered by the Nielsen 
Company from January to October 2009, 
Apple's 3G iPhone rates as the top mobile 
device in use among U.S. users, with a 4% 
share. RIM's BlackBerry 8300 Series, which 
includes the Curve, follows with a 3.7% 
share. RIIVI's 9530 Series (Storm) ranks as 
the seventh most used mobile device (1.4%), 
while the 8100 Series (Pearl) ranks at No. 10 
(1 .2%). IVIotorola's Razr V3 series sits third 
on the list with a 2.3% share. LG occupies 
the fourth, fifth, eighth, and ninth positions 
with its LG VX9100 enV2 (2.1%), Voyager 
(1.7%), VX9700 Dare (1.3%), and Vu series 
(1.3%), respectively. Samsung's SPH-M540 
(Rant) holds the sixth position at 1.5%. 
Overall, LG's models account for a 6.4% 
share of the market, while RIIVI's account for 
a 6.3% share. 

I President Obama 

Names Cybersecurity Leader 

Late last month. President Obama named 
Howard Schmidt, president and CEO of the 
ISF (Information Security Forum), as the 
national cybersecurity chief. Schmidt, who 
will reportedly have direct access to Presi- 
dent Obama, previously served as a cyber- 
security advisor to President Bush and also 
worked for eBay, Microsoft, and the FBI in 
security positions. Overall, he has more than 
40 years of experience in the security field. 
Among Schmidt's tasks will be shoring up 
cybersecurity policies among various federal 
government agencies, including the military. 
He will report to John O. Brennan, deputy 
national security advisor. 




I More Wireless Broadband 
Spectrum Needed 

As many U.S. citizens are still without broad- 
band Internet access, the Antitrust Division of 
the Department of Justice believes that wire- 
less broadband may be a viable competitor to 
wired broadband. However, in order for wire- 
less broadband to be competitive, the DOJ 
has asked the FCC to release additional wire- 
less spectrum. Other entities have sent simi- 
lar letters to the FCC in recent weeks, as 
well. Use of wireless broadband has explod- 
ed with the growth of smartphone use, and 
networks are experiencing heavy traffic — 
most notably AT&T, which is the exclusive 
carrier for the iPhone. 
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New Report Shows 
Hiring, Spending 
Increases For Q1 

After a year of high unemployment levels for 
the IT industry, there are signs that ClOs are 
ready to begin hiring once again. According to 
the Robert Half Technology "IT Hiring Index 
and Skills Report," there will likely be a 3% net 
increase in the overall IT workforce for the first 
quarter of this year. The report, which sun/eyed 
more than 1 ,400 ClOs from U.S. companies 
with 100 or more employees, found that 7% of 
ClOs plan on hiring new workers in the work- 
force and 4% will likely reduce their staffs. 
These numbers are the best outlook the IT 
industry has had since the first quarter of 2009. 




"IVIany companies have cut IT staff levels too 
deeply during the past year, making it chal- 
lenging for IT departments to keep pace with 
rising workloads," says Dave Willmer, execu- 
tive director of Robert Half Technology. "In 
turn, they are looking to bring in extra project 
support who can relieve the burden of exist- 
ing staff and ensure the timely completion of 
mission-critical initiatives." 

Wholesale, Healthcare Lead The Way 

Wholesale ClOs led the pack with 20% of orga- 
nizations planning to hire new workers and just 
4% reporting cutbacks. In the healthcare indus- 
try, 16% of ClOs plan to add staffers and just 
3% expect reductions. The healthcare industry 
has been sparked by government stimulus 
funds designed to help healthcare organiza- 
tions employ electronic health records. 

"The healthcare sector will likely remain a 
bright spot for IT professionals, due in large 
part to the government's stimulus package," 
Willmer says. "In particular, hospitals and 
physician offices need IT professionals who 
can help manage the conversion to electronic 
medical records." 

Willmer says he was most surprised that four 
in 10 ClOs were confident that their firms will 
invest in IT projects in the first quarter. Ac- 
cording to Willmer, when sun/ey respondents 
were asked to rate on a scale of one to five 
how confident they are in their company's like- 
lihood to invest in IT (one being least confident 
and five being most confident), 23% rated their 
confidence level a five and 19% said four. 

"While we expected there to be some pent-up 
demand for IT projects, the results suggest 
many IT execs are looking to pull the trigger as 
we head into the first quarter," Willmer says. 

Although the numbers from this sun/ey predict 
spending and hiring increases, Willmer says 
that no general assumptions should be made 
about how the U.S. economy will fare in 2010. 
While ClOs are optimistic, it's still just a small 
part of the overall picture, he says. 

by Tessa Warner Breneman 
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Effective Business Continuity 
& Disaster Recovery 

Neverfail's Continuous Availability Suite Helps Protect SMEs 
From Business-Threatening Downtime 



by Sixto Ortiz Jr. 

Because enterprises use such a wide 
variety of applications, it is critical that a 
disaster recovery and business continuity 
product work by focusing on the ecosystem 
of applications that comprises business 
workflow processes. Focusing on just sin- 
gle applications neglects the big picture 
and may lead to incomplete results when 
it comes to protecting a business from dis- 
aster. With its business process-centric 



appUcation can take down an entire business 
process. Thus, managing availability across 
an entire business process is important. 

For example, multiple applications can be 
grouped by business function or region, 
ensuring that entire business processes are 
continuously available. Also, the console 
serves as the central control point to manage 
unique features in Neverfail, such as dedu- 
pUcation-based WAN acceleration, multitier 
replication, and application-centric failover 
with seamless switchback. 




neverfaii 



Neverfail Continuous Availability Suite helps SIVIEs prevent costly 
downtime by aiding in business continuity and disaster recovery. 



approach to business continuity and disaster 
recovery, Neverfail successfully embraces 
this concept. 

Neverfail (www.neverfailgroup.com) 
speciaUzes in providing software that helps 
enterprises protect themselves against the 
negative effects of IT outages. In that sense, 
Neverfail's offerings can be used by small 
to midsized enterprises as a component of 
their business continuity and disaster avail- 
ability plans. 

According to Neverfail, its Continuous 
Availability Suite ensures that business 
applications such as email, databases, and 
collaboration remain available 24/7, even 
when disasters occur. 

A View for Applications 

Neverfail's Continuous Availability Suite 
is designed to protect what the company 
calls "application ecosystems" by using 
continuous replication, application monitor- 
ing, self-configuration, and automated 
failover. For example, by continuously 
replicating data from active to passive 
servers, Neverfail can clone an application 
environment, thus providing protection not 
just for single, discrete applications but for 
business processes that comprise multiple 
applications working together. 

Andrew Barnes, senior vice president of 
corporate development at Neverfail, says 
that the Neverfail 6.2 graphical user inter- 
face provides a single view into the avail- 
ability of all applications on every system. 
According to Barnes, this console greatly 
simplifies the visualization and management 
of application availability on all systems. 

Administrators can use Neverfail's GUI 
to manage the availability of their mixed 
environments and keep users working even 
when multiple software applications 
go down. Business processes consist of 
multiple applications, so failure of any one 



AAA: Application 
Availability Automated 

The Neverfail compo- 
nents — Neverfail Heart- 
beat, Neverfail Low Band- 
width Module, and various 
plug-ins for support of 
applications such as Micro- 
soft Exchange, IBM Lotus 
Domino, SharePoint SQL 
Server — are designed to 
keep business users con- 
nected to mission-critical 
applications despite IT out- 
ages that could affect appli- 
cation availability. 
According to Barnes, Neverfail takes the 
approach that if any one application fails, 
there is a significant impact on business pro- 
ductivity, profitability, and reputation. The 
Neverfail suite eliminates user downtime by 
proactively monitoring the availability of 
applications and by maintaining clones of 
those applications elsewhere, such as an 
additional local server or at a remote disas- 
ter recovery center. If an application fails, 
says Barnes, the end user continues to 
work on the alternative server. Neverfail 

never fail 

WWW.NEVERFAILGR0UP.COM 

PREDICT ■ PROTECT ■ PERFORM 

automates the process of switching multiple 
applications to alternative systems. 

The Difference 

Neverfail's applications are unique, says 
Barnes, because they provide continuous 
availability not just for individual applica- 
tions, but also for an extended application 
ecosystem. For example, he says, a Micro- 
soft SharePoint Knowledge Portal that 
depends on SQL servers, index servers, 
and file systems requires an understanding 
of whether any of those components is 
about to fail. Neverfail uses an application 
management framework to protect all of 
those components. 

Any application capable of monitoring 
and preventing the failure of multiple com- 
ponents and applications must be able to use 
multiple tools to get the job done. Neverfail, 
says Barnes, accomplishes the task of pro- 
viding high availability and remote disaster 
recovery using a single product by leverag- 
ing multitier replication, monitoring, 
and failover, which competitive solutions 
cannot do because they mostly provide data 



protection for single applications. Also, 
Neverfail products use synchronization 
between sites and provide seamless switch- 
back when primary systems are restored, 
thus focusing on the user experience. 

Another way Neverfail's solution is able 
to combine disaster protection and high 
availability into one package is via the use 
of what the company calls an optional ter- 
tiary server located outside the local 
network that provides disaster protection 
capabilities. So, protection is provided both 
for local application failures and more wide- 
spread natural or manmade disasters that 
can affect an entire enterprise. 

Performing the work required to ensure 
that application environments exist on alter- 
native servers can result in a severe hit to 
wide-area network performance due to the 
significant amounts of data that must be 
transmitted. Neverfail's optional WAN- 
Smart facility can mitigate this bandwidth 
hit by using data deduplication and com- 
pression techniques to reduce the volumes 
of data that must be replicated across a net- 
work using an organization's WAN. 

A Focus On Business Processes 

In today's business environment, orga- 
nizations need access to all of the applica- 
tions that make up their critical business 
workflow processes. If any of these appli- 
cations — especially those that are 
mission-critical — go down, multiple 
applications may be compromised and 
business activities could even cease, says 
Barnes. And, he adds, as critical applica- 
tions are moved to a virtual platform risk 
increases, so both application and plat- 
form availability are required. 

At first glance, it would appear that a high 
availability/disaster recovery solution would 
have to be constantly tweaked in order to 
accommodate configuration changes due to 
the use of new applications. Depending on 
how frequently these changes occur across 
an organization, this issue could become 
quite troublesome to manage. Neverfail's 
product features automated discovery of 
new configuration changes and applications 
so the product's capabilities remain fresh. 

In addition, flexibility for administrators 
is provided via the use of policies and rules 
that determine how critical applications and 
processes are protected; also, administrators 
have the choice of using either automated or 
manual failover. 

Neverfail Continuous 
Availability Suite 



(512) 327-5777 
www.neverfailgroup.com 

Description: A business continuity and disas- 
ter recovery suite of applications tliat focuses 
on tlie preservation and protection of entire 
business processes, not just applications. 

Interesting Fact: Neverfail is a IVIicrosoft Gold 
Certified partner and has OEIVI relationships 
with several companies, including VMware. 
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HOW TO 



Deploy A Wireless 
Infrastructure 

Get A Grasp On Building Layout, Business Objectives & Employee Needs 



by John Brandon 
• ■ • 

For most IT deployments, the more 
you know about the technology, the better. 
With a wireless infrastructure, there is a 
lot to learn about Wi-Fi radio technology, 
networking backhauls, and security proto- 
cols that can protect company assets and 
keep your network safe. But a thorough 
knowledge of the building layout, non- 
technical needs of employees — such as 
whether they typically need to connect in a 
cafeteria or in a conference room — and a 
good understanding of business objectives 
also come into play during deployment. 
For some SMEs, this might mean setting 
aside any conceptions of how ubiquitous a 
wireless network needs to be and under- 
standing that an "all or nothing" approach 
usually will not work, especially using the 
current wireless standards. 

Planning & Preparation 

As with any major roll-out, a wireless 
infrastructure — one meant to provide easy 
access to the Internet from laptops and 
smartphones or one that provides wireless 
access to business applications — requires 
careful planning and preparation. Ac- 
cording to David Johnson, co-founder of 
and consultant at The Fulcrum Group, 



with our clients is who needs to access 
what and what they need to access." 

Cameron Niles, CTO at IT consulting 
company Syzygy 3, agrees that planning the 
"who and what" is important for the ever- 
changing IT landscape. Companies might 
need to provide access to more than just lap- 
tops and smartphones and should plan for 
employees with IP phones (such as those 
that use Skype or another VoIP provider) 
that use a greater amount of bandwidth. 
Niles says different user groups have very 
different needs: Some require very fast 
access to applications, and others just need 
to check email occasionally in an entryway. 

According to Niles, one trend in many 
companies is to deploy two separate 
wireless networks, one for internal use 
and one for guests. This points to the fact 
that an SME needs to plan for how 
employees and visitors will use the net- 
work and also addresses another initial 
deployment concern: security. 

For many enterprises, the two-network 
approach solves this problem, and Niles 
says that in some cases, a wireless deploy- 
ment will involve a completely separate 
switch that will be used for the "public" 
wireless access and then a separate wireless 
controller that is used for making sure a pri- 
vate company network is secure and not 



Many of the best wireless networking 
companies offer a bevy of tools for 
helping in wireless deployment. 



planning for a wireless deployment means 
determining an appropriate level of access 
for employees and deciding on how to 
provide guest access. 

"Internal office workers may need 
access to IT systems, and you may have 
guests who simply need to get on the 
Internet," says Johnson. "There are other 
types of users, such as vendors and strate- 
gic partners, who need a separate level of 
access. The first thing we usually cover 



TOP TIPS 



According to Ross Rehart, a network man- 
ager at CenterBeam (www.centerbeam 
.com), SMEs should keep these tips in mind 
to help a wireless infrastructure deployment 
go smoothly. 

• Gather requirements for the network and 
know why you need a Wi-Fi network. 

• Conduct a wireless survey to help you 
plan access point locations, both inside 
the company and even in outside areas. 

• Conduct a hardware assessment that 
matches the requirements and deploy- 
ment needs. 

• Run a proof-of-concept for the network 
before deployment to work out the bugs. 



even accessible for guest use. With a wire- 
less controller used for deployment of a pri- 
vate company Wi-Fi network, there is less 
danger of a hacker in the parking lot tap- 
ping in through a widely available access 
point and stealing company information. 

Wireless security is also directly related 
to compliance, says Mark Coltharp, a tech- 
nology solutions consultant for Accuvant. 

"Every SME thinking about a wireless 
deployment should determine whether or 
not it must comply with industry regula- 
tions or standards such as the Health 
Insurance Portability and Accountability 
Act (HIPAA) or Payment Card Industry 
Data Security Standards (PCI DSS)," says 
Coltharp. "SMEs should also look at the 
current infrastructure that's already in 
place for networking and end computing 
devices to evaluate how compatible the 
network is with wireless infrastructure and 
industry standards for wireless." 

Building Considerations 

Interestingly, after planning out who will 
access the network and resolving security 
issues, the next step in the process is not 
necessarily IT-related and involves taking a 
close look at the building structure. This 
may require assistance from a facility man- 
agement team or require that you examine 
building blueprints. According to John 
Jankowski from JanCom Technologies 
(www.jancom.com), building considera- 



Key Points 



• Plan out who will be able to access the 
wireless network and evaluate why they 
need access. 

• Consider the security variables, especial- 
ly for guest access and employee access 
to applications. 

• Examine building floor plans and deter- 
mine where access points should go. 



tions are critical to the success of a wireless 
deployment because it is often difficult to 
know whether a wireless signal can reach 
one particular room or if there is a firewall 
(the kind that is reinforced for a fire, not the 
security device) that could block a signal. 

Jankowski says examining a building 
takes time and thought but can also be an 
intuitive process of just walking around 
the building and deciding where access 
points should be placed for high-traffic 
areas, whether there are outlets available 
or if the network switch supports Power 
over Ethernet, and whether certain groups 
in the building have a greater need for 
wireless access than others. 

One important step in the process is to 
realize that the wireless network will like- 
ly not cover every cubicle and every desk. 
In fact, Jankowski says you should con- 
centrate on areas that meet a specific need 
for remote access. He says the high-traffic 
areas, such as a conference room, may 
even need multiple access points, whereas 
a group in another corner of the building 
may not need access. 

Helpful Tools 

Many of the best wireless networking 
companies offer a bevy of tools for helping 
in wireless deployment. These tools can 
provide a basic knowledge of how access 
points will interconnect and any need for 
wireless backhaul to handle congestion. 
Jankowski notes that, unlike a wired net- 
work where each user connects into a server 
through a separate connection, a wireless 
network is automatically a choke point 
because of how a wireless network allows 
multiple connections that feed into a switch. 
Software tools — which might feature data 
visualization techniques — can help deter- 
mine where congestion might occur. 

That said, even the best software tools, 
which are sometimes designed only for 
specific kinds of deployments, cannot 
replace a good planning stage that exam- 
ines specific building issues and addresses 
how the company will resolve wireless 
congestion issues that may arise. 

Once a plan is in place, the next step is 
to choose the products and technologies 
that match the needs of the company as 
well as the overall plan for where you will 
deploy access points. Once the products 
are selected, the deployment phase can 
begin, followed closely by monitoring the 
new wireless infrastructure and providing 
maintenance to address any wireless 
access problems. 




Fraudsters 
Circumventing 
Two-Factor 
Authentication 
Protection 

strong two-factor 
authentication meth- 
ods apparently aren't 
what they used to be, 
according to recent 
research that Gartner 
released stating that fraud- 
sters using 'Trojan-based, man- 
in-the-browser attacks are circum- 
venting strong two-factor authentica- 
tion, enabled through one-time pass- 
word tokens." Additionally, alternative 
strong-authentication factors, includ- 
ing ones using chip cards and bio- 
metric technology that rely on brows- 
er communications, are capable of 
falling to malicious users' tactics. 

In a report released in December titled 
"Where Strong Authentication Fails and 
What You Can Do About It," Avivah Litan, 
Gartner VP and distinguished analyst, states 
that such attacks, including the circumvention 
of two-factor authentication based on telepho- 
ny, were repeatedly carried out against banks 
and customers globally in 2009. In the case of 
telephony circumvention, Gartner reports that 
malicious users are "using call fon/varding so 
that the fraudster, rather than the legitimate 
user, is called by the service provider perform- 
ing the authentication." 

To date, bank accounts have been the prima- 
ry target of such attacks, Gartner reports, but 
"these attack methods will migrate to other 
sectors and applications that contain sensi- 
tive, valuable information and data within the 
next three years." 

Gartner states that its clients that have suc- 
cessfully warded off such attacks have been 
able to do so by using automated fraud 
detection or by manually reviewing high-risk 
transactions. Further, some enterprises using 
telephone-based user authentication and 
transaction verification are contemplating 
stopping phone calls from going to the user 
when it proves feasible if a carrier forwards 
calls and texts to a different phone number, 
Gartner reports. 

Litan says that small enterprises in particular 
are at risk because "they don't know about 
this," "they don't know what to do about it," 
and "they tend to not be as diligent about 
security matters" as larger organizations. Litan 
suggests that enterprises use a three-fold, 
layered fraud prevention approach that com- 
bines out-of-band transaction verification and 
signing for high-risk transactions, enhanced 
authentication, and fraud detection. 

Overall, Gartner recommends that enterprises: 

• Realize that any authentication method 
communicating via a Web browser is sus- 
ceptible to being defeated and compro- 
mised; thus, enterprises should put addi- 
tional security measures into place 

• Monitor transactions for suspicious behav- 
ior by using server-based fraud detection 

• Verify users' transaction requests by using 
out-of-band transaction verifications and 
carrying out only specific transactions that 
a requesting user verifies or signs 

• Prevent calls from being forwarded to 
numbers unregistered to a specific user 
account via the use of out-of-band com- 
munication protocols 

by Blaine Flamig 
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Budget-Friendly 
Managed Services 

DataVelocity Offers Monitoring, Asset IVIanagement & IVIore To SIVIEs 



by Holly Dolezalek 

With some IT companies, it's hard to 
sum up their niches without sounding like 
a software manual. But in the case of 
DataVelocity, it's easy: The company is a 
well-known managed service provider in 
the Big Apple. 

Since 2002, DataVelocity has had its 
headquarters in Woodland Park, N.J., but 
the privately owned company has an 
office in New York City, as well, and its 
target market is mostly the small to medi- 
um-sized enterprise. 



There's no shortage of MSPs, whether 
nationwide or in NYC, but DataVelocity 
has the odd distinction of having leader- 
ship that understands the IT budget — 
both the unlimited kind and the shoe- 
string kind. One of DataVelocity' s co- 
founders is Adam Warshaw, who came 
from the financial sector and has seen a 
lot of the "big sack of money" approach 
to IT budgeting. But the other is Melissa 
Minchala, whose days at nonprofits 
taught her a lot about how to keep IT run- 
ning when budgets are a couple of exits 
beyond limited. "Based on our back- 
grounds, we can advise companies on the 
tradeoffs they'll be making no matter 
what the budget is," says Warshaw, who 
serves as DataVelocity' s president. "We 
can talk to them about, 'If you're going 
to spend $1,000, how will that help?' or 
'If you're only going to spend $100, will 
you get alarms every day?'" 

Taking Care Of IT 

DataVelocity' s managed service plans 
include continuous monitoring, asset man- 
agement, capacity planning, security 
assurance, and other similar services. Most 
of what the company does is done remote- 
ly, although some physical problems (such 
as a server crash or desktop problems that 
require onsite interventions) mean an in- 
person visit. The company offers different 
levels of service at different price points, 
although most services are the same. The 
plans vary in terms of response time for 
servers or desktops (three plans offer four-, 
two-, or one-hour response times) and 
desktop support hours. 

Warshaw explains that one of the selling 
points for DataVelocity 's managed service 



plans is its monitoring services. Its core 
offering is the technology support that lets 
customers focus on what they do best 
instead of fiddling with IT, but one aspect 
of that is keeping an eye on the IT envi- 
ronment once it's in place and taking 
proactive action when problems crop up. 
"If a customer's server goes down, we fix 
it first, but we also monitor it and if it's 
starting to have issues, we fix it before the 
problem reaches a business-impact level," 
Warshaw explains. 

Some customers aren't in a position to 
use the full monitoring where DataVelocity 



takes care of the fixes. But the company 
offers the option of doing the monitoring 
from a distance, so to speak. It does the 
same monitoring but leaves the actual ser- 
vice to the IT staff at the customer's site. 
"We might reach out to that IT staff person 
and tell them that before they go home 
tonight, they need to change a disk," 
Warshaw says. 

Value-Adds 

There are other offerings that increase 
DataVelocity ' s attractiveness for the 
company's target market, which includes 
plenty of financial services firms, law 
firms, and other kinds of professional 
services companies such as accountants 
and financial advisors. But almost any 
company might need to hand over its IT 
support problems to someone else, 
Warshaw points out; for example, 
DataVelocity has one client in the meat 
wholesale business. 

One of those offerings is Virtual CIO, 
which is part of DataVelocity 's managed 
service package. Virtual CIO is a sort of 



support line for IT-related questions that 
don't have to do with current problems or 
applications. For example, one of the com- 
mon questions that customers ask of 
Virtual CIO is, "What kind of a cell phone 
should I get?" 

"Our customers call in, and since we 
know their technology environment, we 
can give targeted suggestions and 
explain the pros and cons of each," 
Warshaw says. "Based on where they're 
going, we can help them get the infra- 
structure they need without buying 
throwaway technology. For example, if 
we know they're ramping up remotely or 
interested in an enterprise firewall, we 
can explain that they should avoid buy- 
ing certain desktops or suggest a firewall 
that can handle that ramp-up in the 
remote environment." 

Another offering is online backup, 
although that one doesn't make sense for 
all of the company's customers. Some 
companies, due to regulatory require- 
ments, need a certain level of backup, 
both offline and a local resource backup. 
But others don't have compliance issues 
and don't need to pay for a complex 
backup scheme. 

Selling The Services 

The lion's share of DataVelocity' s busi- 
ness is in the United States, specifically 
the New York City area. Occasionally, the 
company provides support to high-level 
employees of customers while they're in 
other parts of the world. 

Most of DataVelocity's sales come 
through the efforts of direct salespeople 
and networking with existing customers 
and other sources of business. The com- 
pany used to work the trade shows, but 
hasn't done it lately because it hasn't 
been as effective as it used to be. Direct 
sales account for 80 to 85% of Data- 
Velocity's revenues. 

The rest come from referrals and from 
the company's channel partners, a small 
number of contract salespeople who sell 
DataVelocity's services. They are not 
direct employees of DataVelocity, 
but they earn a commission based on 
their sales. In days to come, Warshaw 
says, the company will be trying to 
increase its presence in social media in 



the hopes of driving more sales. That 
means a presence on Twitter, Facebook, 
and YouTube. 

On The Horizon 

The shift from 32-bit computing to 64- 
bit is driving a lot of change for 
DataVelocity. For its larger customers, the 
change isn't as big a deal; Exchange 2007 
only runs on 64-bit, but for companies that 
have multiple servers, they can run 64-bit 
applications on some servers and 32-bit on 
others. "For our smaller clients, who may 
only be running one server, you can't just 
tell them to switch to a 64-bit server 
because some of their applications might 
not be ready for that," Warshaw explains. 



DataVelocity 



For DataVelocity, that means setting up 
virtualized 32-bit servers so that compa- 
nies with only one physical server can still 
run their applications on the architecture 
they require. 

Interest in cloud computing is increas- 
ing, as well, although Warshaw says that 
DataVelocity's role has been more of edu- 
cation than of application so far. "We're 
talking to them about the constraints 
they're trying to solve with the cloud or 
about transitioning some applications from 
the cloud to an in-house solution and the 
factors they need to think about either 
way — uptime, price breakpoints, and so 
on," he explains. 

This year, Warshaw expects that 
DataVelocity will add some new posi- 
tions, as it did last year, to deal with a 
growing customer base. It's also experi- 
menting with developing solutions for 
mobile devices as a value-add to their 
existing stable of features in the service 
plans. And the company is working to stay 
up on the latest IT developments, whether 
it's the cloud or security or mobile 
devices, so that they can give their cus- 
tomers the advice they need to buy the 
right technology. "We try to help them 
make the smartest buy for the business 
dollar," Warshaw says. 



DataVelocity Support Service Plans 



1 Service 


Server Response Time 


Desktop Response Time 


Desl<top Support Hours 1 


Bronze 


4 hours 


4 hours 


Monday through Friday, 
9 a.m. to 5 p.m. 


Silver 


2 hours 


4 hours 


Monday through Friday, 
7 a.m. to 7 p.m. 


Gold 


1 hour 


2 hours 


Monday through Friday, 
24 hours a day 




DataVelocity 



(800) 835-0102 
www.datavelocity.com 

• DataVelocity is a managed service 
provider geared toward small to midsized 
enterprises that specializes in helping 
SMEs work with their budgets, no matter 
how limited or generous. 

• The company offers an advisor called 
Virtual CIO that aids in answering day- 
to-day noncritical IT questions. 

• "We try to help [our customers] make the 
smartest buy for the business dollar," 
says Adam Warshaw, DataVelocity presi- 
dent and co-founder. 



January 15, 2010 



Processor.com 



Page 27 



SECURITY 



FEATURED COMPANY 



Steganalysis 
Experts 

Backbone Security Keeps Valuable Data 
From Slipping Out Under Cover 



by Robyn Weisman 

Just when you think you have your net- 
work security under control (assuming that 
is even possible), something you never 
considered has to show up and make your 
job that much more complex. And so it 
goes with steganography, a technology 
that lets a seemingly innocuous photo or 
avatar store surprisingly large amounts of 
information, including your customers' 
credit card information, PHI (private 
health information), and your company's 
intellectual property. 

In 2004, IT security provider 
Backbone Security (www.backbone 
security.com) launched its Stega- 
nography Analysis and Research 
Center, or SARC, to research and 
develop solutions to counteract this 
growing danger. "SARC's goal is to 
be the world's leading provider of 
digital steganalysis software and to 
provide users with computer foren- 
sic and network security tools to 
detect insider use of steganography 
to steal sensitive information or 
otherwise conceal evidence of crim- 
inal activity," says Jim Wingate, 
director of SARC and Backbone 
vice president. 

When Backbone Security was 
incorporated on Sept. 11, 2000, its 
goal was to provide full-service 
enterprise information security soft- 
ware and services. The company 
still positions itself as having a 
strong portfolio of IT security ser- 
vices to this day. However, Backbone's 
specialties in steganalysis at SARC and in 
PCI compliance assessments and solutions 
are two areas worth understanding and 
consideration as our world continues 
its push toward total interconnectivity and 
the borders between individual data cen- 
ters and everything else become increas- 
ingly blurred. 

Cracking The Code 

Wingate says that most organizations, 
no matter their size, have confidential 
information they must maintain control 
over, and he knows it isn't news that insid- 
ers stealing information is a constant 
threat. But too often, the image of the 
nefarious insider absconding with compa- 
ny secrets consists of someone sneaking 
out the back with the information on a 
thumb drive or perhaps emailing it to 
another party. But as more and more orga- 
nizations deploy DLP (data loss preven- 
tion) solutions and encryption tools, 
potential data thieves are moving toward 
more sophisticated ways of hiding infor- 
mation, such as steganography, which is a 
method of protecting confidential data by 
hiding it within another file. 

"You might think the word 'steganogra- 
phy' would just never pop into their heads. 



but information hiding certainly would, 
and if you do a Google search on informa- 
tion hiding, you'll get several million 
hits," Wingate says. "Many of these hits 
will lead you to sites [with] steganography 
applications you can download, install, 
and use." 

According to Wingate, many of these 
steganography applications are a cinch 
even for technology-challenged people to 
use. "They have wizard interfaces or drag- 
and-drop interfaces," says Wingate. For 
those who are skeptical of this option really 



apple is churning out data-filled avatars, 
not when strapped IT departments have 
to worry about employees accidentally 
posting confidential information on a 
Web site or leaving their smartphone 
stuffed with credit card numbers in a 
cab. "But if you're not explicitly look- 
ing for it, you're never going to detect 
it," Wingate says. "After all, it's not the 
sort of thing that jumps up and hits 
you between the eyes with a two-by- 
four! The whole purpose of using steg- 
anography is to remain covert and not 
get caught." 



combat cybercrime. Steganography was 
mentioned as one of the tools, which fur- 
ther piqued Wingate's interest in learning 
more about the technology. Not long after 
that, Wingate got a call from his boss about 
good projects to do in north central West 
Virginia (where SARC is now located), and 
Wingate suggested starting a steganography 
I research center. Wingate wrote a white 
paper, which Backbone gave to West 
Virginia Congressman Alan MoUohan, and 
the company received grant funding to 
estabhsh SARC. 

PCI Compliance Services 

Backbone Security's other core offering 
is PCI DSS (Payment Card Industry Data 
Security Standards) compliance services; 
in fact. Backbone is an Approved 
Scanning Vendor. 

Rob Yoka, director of the PCI compli- 
ance division at Backbone Security, 
explains that one of the requirements for 



Backbone Security 



(888) 805-4331 

www.backbonesecurity.com 

• Backbone Security's Steganography 
Analysis and Researcin Center provides 
steganalysis services that can help SMEs 
find confidential information hidden in 
larger sets of data. 

• As an Approved Scanning Vendor, the 
company also provides help with PCI 
DSS compliance. 

• "We are able to give [SMEs] that higher- 
level analysis that they wouldn't be able 
to get otherwise with their own in-house 
staff," says Rob Yoka, director of the 
PCI compliance division at Backbone 
Security. 



maintaining compliance under the PCI 
DSS is to conduct quarterly vulnerability 
scans and assessments. "We look for a 
variety of vulnerabilities, mostly having to 
do with Web technologies, Web applica- 
tions, cross script SQL injections, and a 
whole range of other potential weakness- 
es," Yoka says. 

Backbone Security not only performs 
these quarterly scans, it also does penetra- 
tion testing and internal vulnerability 
assessments. "A vulnerability assessment 
identifies the avenues that may leave you 
open to a hacker or attacker coming in and 
exploiting your information," Yoka says. 
"The penetration test is actually taking the 
next step and seeing, 'Yes, this is an 
avenue that can be attacked,' or 'No, 
maybe there needs to be some other fac- 
tors involved too for someone to success- 
fully get in.'" 

Backbone Security offers what it calls 
one-stop PCI solutions to organizations of 
all sizes for as little as $229 per year. 
Yoka says it is an especially good deal for 
SMEs that may not have the people, 
money, or time to stay on top of these reg- 
ulations. "Even if they buy the tools and 
run them, they don't necessarily know 
how to interpret the results or figure out 
what a false positive is vs. something that 
is a real vulnerability," Yoka says. "There 
also may be data across a variety of hosts 
that maybe doesn't flag as a vulnerability 
on each host, but taken together, there may 
be some vulnerability in the way things 
are architected," he adds. "We are able to 
give that higher-level analysis that they 
wouldn't be able to get otherwise with 
their own in-house staff." 



BACK 
BONE 

SECURITY 



being used in the near term, there is even 
an iPhone steganography app called 
PrivateTIP that allows users to encode and 
send Twitter-length pieces of information 
inside images. 

Of course, data center managers may 
not have time to worry that every bad 



The Start Of SARC 

SARC, an entity that exists within 
Backbone Security, provides cus- 
tomers with stegananalysis solutions 
rather than what Wingate terms a 
steganography solution. "Steganog- 
raphy is hiding it, whereas ste- 
ganalysis is finding it and extracting 
it," he says. "At SARC, we devel- 
oped software to detect the presence 
or use of steganography and then 
extract it and in some cases decrypt 
it if it was encrypted before it 
was hidden." 

Wingate explains that SARC 
came into existence as a result of 
Wingate's 25 years of experience 
working as a communications and 
information officer in the U.S. mili- 
tary. When Wingate retired and first 
started working at Backbone 
Security, he taught information 
assurance courses (military parlance 
for computer security courses). One of the 
classes he taught was a four-day course on 
types of covert channels, of which 
steganography is one. 

After 9/11, Wingate got a document from 
a friend in the FBI about the tools and tech- 
nologies needed by law enforcement to 



Backbone Security 
Featured Products & Services 





Product 


Description 


Enterprise Information 
Security Assessment 


1 

An in-depth info-sec evaluation of an enterprise's network that looks 
for vulnerabilities within the network's architecture and provides 
recommendations for fixing them. 


DSD IVIanaged Services 


Proactive and available managed support services that can monitor 
and support data centers 24/7. 


PCI DSS (Payment Card 
Industry Data Security 
Standards) Compliance 
Services 

SARC (Steganography 
Analysis and Research 
Center) 


An ASV (Approved Scanning Vendor) PCI DSS solution that 
includes comprehensive technical and compliance support. 

State-of-the-art steganalysis products and services that enable 
organizations to detect and extract hidden information from images 
and other files. 
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Trend Micro: Tech 
Threats Are Sure To 
Increase 

Looking ahead to the types of threats data 
centers will face in the next 12 months neces- 
sitates both a thorough examination of the 
previous year's security challenges and the 
current patterns developing on the technolog- 
ical landscape. Trend Micro's annual threat 
report outlines the trends observed in 2009 
and interprets any looming cyber challenges, 
especially in cloud environments. 

In its report titled "The Future of Threats and 
Threat Technologies: How the Landscape Is 
Changing," Trend IVIicro revealed that the 
2009 predictions came true regarding the 
threats with social networking, social engi- 
neering, and the underground tech economy. 
The 201 forecast appears to be no less 
challenging with risks emerging in numerous 
tech sectors, including Windows 7, alternative 
operating systems, virtualized environments, 
and corporate social networks. Attacks will no 
longer overtake systems on a global scale 
but will be localized and engage specific tar- 
gets. IVIalware and other infections will have a 
mind of their own, taking new forms and con- 
taminating PCs in a single visit. 

In the coming year, it's expected that cyber- 
criminals will see more ransomware-type 
attacks, in which the attacker confiscates the 
user's Web connections or data for cash. They 
will also utilize social manipulation to gain 
access into the social media "circle of trust," 
where users unknowingly click malicious notifi- 
cations and pop-ups only to become victims of 
a cyber attack. Other threats to the user include 
tainted hardware, poisoned searches, malver- 
tisements, and application vulnerabilities. 

Cloud Coverage 

With more and more data centers moving to 
the cloud model, enterprises must pay atten- 
tion to the security risks associated with cloud 
adoption. Trend Micro points out that although 
public cloud success, cost savings, and com- 
petition will drive enterprises to commit to 
cloud computing, threats to SaaS/PaaS com- 
puting and laaS are real. Therefore, operating 
systems, hypen/isors, and applications must 
remain protected. Data center administrators 
will also need to be aware of side-channel 
attacks, malicious DDoS traffic, and vulnerable 
BGP (Board Gateway Protocol) technologies. 

To mitigate these risks. Trend Micro recom- 
mends deploying security solutions that are 
cloud-oriented. Companies can also take 
responsibility for security updates by check- 
ing security blogs and other informational 
sites that track threat trends. To protect cus- 
tomers, it's wise not to send "phishy" mes- 
sages, says Trend Micro, that include re- 
quests for personal data, redirectors, and 
pop-ups, among others. 

Much of this advice falls under the "nothing 
new here" category, but it's not worth disre- 
garding. Enterprises are always encouraged 
to deploy consistent protection, prepare for 
attacks, protect customers via prevention, 
take cybersecurity precautions, and 
always employ a plan for systems res- 
olution and restitution. 
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Encryption B lueprint 



Implementation & Management Tips For SMEs 



by Christian Perry 

Keeping up with the big boys when it 
comes to encryption is easier said than 
done. A recent Aberdeen Group study 
found that best-in-class companies have 
successfully deployed and managed 
encryption technologies to reduce data loss 
and data exposure incidents by 4% from 
one year ago. Compared to others, best-in- 
class companies currently support encryp- 
tion in about 40% more applications. 

Yet despite the proven success realized 
by implementing encryption, few small 
and midsized enterprises are using it. 
"Most organizations have not developed 
clear policies regarding use of encryption 
technology, and even those that have do 
not have a clear mechanism for enforce- 
ment of these policies," says Ken Liao, 
senior product marketing manager at 
Proofpoint (www.proofpoint.com). 

The typical SME already has limited 
resources to devote to security, and 
encryption complicates matters, though 
today's encryption technologies won't 
necessarily add a huge burden to the 
security team's slate. The biggest road- 
block with encryption doesn't revolve 
around the technology itself, but instead 
the myriad issues that surround its use. 

Wading Through Challenges 

Even when encryption is in place, 
SMEs aren't always doing a great job of 
ensuring it hits all possible access points. 
Bill Mackey, a subject matter expert in 
Compuware's Commercial Field Enable- 
ment group (www.compuware.com), 
says that organizations that do work with 
encryption spend much of their efforts 
locking down production systems and/or 
encrypting data going outside of the 
organization. Further, he says their pro- 
duction data is usually not encrypted but 
is generally protected by security pack- 
ages with role-based access. 

"While there is hardware encryption 
available, I have seen very little of it in use 
so far," Mackey says. "The most vulnera- 
ble area that I see is when companies move 
production data into their testing environ- 
ments, which typically does not have secu- 
rity controls in place like the production 
environment has. Testers, QA people, 
developers, and contractors often have free 
access to data that would otherwise be 
secure in the production environment." 

Encryption presents many challenges 
to organizations, which can prompt 
adopters to take varying paths to encryp- 
tion — or simply the easiest approach. 
Mackey says that from an organizational 
perspective, just defining ownership of 
the data is a big decision. For example, 
who will take responsibility for it once 
it's encrypted? Who will enforce the dis- 
guise processes to ensure that all users 
accessing the data are compliant? What 
standards will be used on the data? How 
does the organization make sure that the 
disguise requirements are also meeting 
business requirements? Does the organi- 
zation need to establish a committee to 
design and implement corporate disguise 
policies and procedures? 

"Political challenges can also hinder a 
complete implementation," Mackey 
adds. "Communication is critical to this 



Key Points 



Best-in-class companies are moving 
forward with encryption, but most small 
and midsized enterprises aren't using 
encryption as effectively as they could. 

Implementing encryption spawns a wide 
range of policy- and procedure-related 
questions that must be addressed to help 
organizations best determine how to 
integrate the technologies. 

Managers must work to identify not only 
what data needs to be encrypted, but also 
which employees need access to the data 
and what levels of access they require. 



initiative. Will all the application groups 
participate in this initiative? Will we be 
able to agree on what needs to be accom- 
plished? There are also external influ- 
ences that can impact this initiative, such 
as auditors that are requiring certain con- 
trols and processes. And then there are 
the technical challenges. Most compa- 
nies have a variety of data types on mul- 
tiple platforms. In some cases, the same 
data may reside on different platforms 
and have different formats. This adds to 
the complexity of disguising data across 
multiple environments while maintain- 
ing consistency." 

Strategy Session 

The wide range of questions surround- 
ing a potential encryption implementa- 
tion requires data centers to step back 
and look around. Daniel Tobin, director 
of operations for information and tech- 
nology services at the Rochester Institute 
of Technology, recommends assessing 
risks and requirements based on protect- 
ing data in transit and at rest, as well as 
defining needs around whole disk vs. 
file-based solutions. Gaining an under- 
standing of what it takes to support these 
environments is crucial for not only day- 
to-day operations but also for disaster 
recovery, he says. 

"It starts with information handling 
and management, combined with a prac- 
tical risk assessment. Plan on employing 
appropriate encryption technologies for 
your most sensitive data first, in a man- 
ner which is auditable. Protecting the 
data but not being able to 'prove' that it 
was protected is not really a solution. I 



don't believe in encrypting data just 
for the sake of encryption — at least not 
yet. As technologies mature, this may 
change," Tobin explains. 

Part of the planning process involves 
identifying which data needs to be pro- 
tected, and proactive SMEs will identify 
and prioritize these specific assets, says 
Nora Cox, product manager at Entrust 
(www.entrust.com). Once a plan for estab- 
lishing security around sensitive informa- 
tion is in place, along with policies for 
authentication to those specific resources, 
managers need to address appropriate lev- 
els and types of security measures. Cox 
says this threshold is typically based on 
the level of risk associated with the conse- 
quence of data being accessed by unautho- 
rized persons or machines. 

Donning investigator caps also helps 
SMEs ensure their encryption implemen- 
tations go smoothly. For example, follow 
the data to make sure that the encryption 
is implemented throughout the entire 
process, advises Randy Barr, chief securi- 
ty officer of Qualys (www.qualys.com). 
Also, when data centers find that encryp- 
tion implementation isn't feasible during 
part of the process, it's wise to collaborate 
with other departments to implement con- 
trols such as monitoring or removal of the 
data, Barr adds. 

The Key Is In the Keys 

A final word of advice from the in- 
ventor of SSL (Secure Sockets Layer) 
encryption: Get your key management in 
order. "Key escrow is always a complicat- 
ed issue that data centers need to support," 
says Dr. Taher Elgamal, chief security 
officer at Axway (www.axway.com). "If 
the data center is down, then the business 
needs to recover the encryption keys 
somehow and enable customers to contin- 
ue to get access to their data. Application 
encryption needs more sophisticated key 
management," he says. 

For example, if the data is encrypted in 
the application layer, direct access will 
always produce encrypted data. To 
access the unencrypted data, the right 
application with the right keys and 
access rights is necessary. Taher notes 
that simple encrypted storage support 
from vendors isn't always sufficient, so 
applications need to be designed correct- 
ly and integrated with the directory to 
allow for proper implementation of 
access control policies, u 



A Team Effort 



The chances of a successful encryption implementation skyrocket when organizations 
integrate teamwork into the process. Randy Barr, chief security officer of Qualys (www 
.qualys.com), says that collaboration with other internal departments is key to developing 
an encryption plan and strategy. 

"Take into consideration who is going to own pieces of the project once completed. For example, 
develop or update internal policies, and rotation of the encryption key may be managed by the 
security team. Backup of encrypted data may require the operations or IT/IS department to own 
this process," Barr says. 

He also recommends collaborating with the right departments and reporting the results 
to avoid potential performance-related problems caused by encryption. For example, 
organizations must determine where keys are stored and who has access to them. In this 
area, Barr notes that implementing separation of duties is an ideal solution when it comes to 
key protection. 



January 15, 2010 



Processor.com 



Page 29 



SECURITY 



THREE QUESTIONS 



Lighten The 
Security Load 

ETSec Helps SMEs Protect Their LANs 

Through Products, Managed Services & Expertise 



by Daniel P. Dern 

The need for network security never 
goes away; if anything, it gets more 
important and complex. One solution 
for many companies, especially small 
to medium-sized ones, is to provision 
network security tasks as managed 
services, which reduces the capital IT 
costs along with staffing and over- 
head expenses. 

One company that's been enabling 
this transition is ETSec (www.etsec 
.com), an information security and 
managed services company that protects 
the network, data center, and informational 
assets for enterprises and other companies. 

Since its inception in 2002, ETSec has 
expanded and evolved its offerings by 
incorporating TrustELI, previously a sub- 
sidiary started by ETSec to offer the 
TrustELI Network Security Appliance, 
and by purchasing MedAvant Healthcare 



Solutions, which offers healthcare technol- 
ogy and transaction services. Today, 
ETSec offers security not just through 



products but also as managed security 
cloud services. Curtis Blount is ETSec' s 
chief strategist and security officer. 

■ What are the biggest IT-related 
issues facing today's small to mid- 
sized enterprise? 

There are a lot of security-related issues, 
especially for smaller companies that do 



not have the necessary in-house security 
expertise to sufficiently protect their envi- 
ronments, according to Blount. "These 
include data breaches and Web applica- 
tions security, followed by PCI (Payment 
Card Industry) security, identity theft, and 
personal data protection," he says. 

■ What should Processor readers know 
about your company's products? 

ETSec protects company infrastructures 
and also secures sensitive data such as 
invoices and financial and healthcare 
records by protecting, maintaining, and 
delivering it securely across the enterprise. 

"We do professional security consulting 
and are an MSP security provider and a 
product integrator," says Blount, who 
explains that his company has an exten- 
sive portfolio of managed security solu- 
tions and services, in addition to 
patented technologies and a wealth 
of industry expertise that includes 
top security and IT certifications. 
ETSec' s customized Web portal lets 
its customers get enterprise-grade 
security without the management 
challenges often associated with 
advanced networking. 

According to ETSec, its MS-Cloud 
Services help address the security 
needs of companies of all types and sizes, 
including highly distributed companies 
and companies with large constituent 
bases and increasingly mobile workforces. 
"We are mostly in seven verticals, [includ- 
ing] financial, retail, health care, manufac- 
turing, insurance, and our OEM vertical," 
says Blount. ETSec's cloud services 
approach lets enterprises extend managed 



services to branch and remote locations, 
telecommuters and other remote employ- 
ees, B2B customers, and even individual 
customers within larger companies. 

In addition to its own products, ETSec 
partners with such industry leaders as 
Check Point, Cisco, Forescout Technol- 
ogies, Juniper Networks, netForensics, 
Nokia, and RSA. 

■ What makes your company unique? 

According to Blount, ETSec provides 
education, training, and certification on 
enterprise security best practices, security 
awareness, and other topics, along with 
security testing, consulting, technical 
assistance, and customized support includ- 
ing help desk services and SLAs. 

"We develop our own security technolo- 
gy as well as provide hosted managed ser- 
vices — including managing products from 
other vendors — for enterprise customers," 
says Blount. "We develop our own hard- 
ware and software; we have eight hard- 
ware and software patents so far. One of 
the first was a consumer-based UTM (uni- 
fied threat management) device, the ELI." 
ETSec is continuing to build new solu- 
tions ranging from enterprise-level down 
through consumer-level, helping its cus- 
tomers proactively keep ahead of near- 
term threats cost-effectively as well as 
creating strategies that will minimize 
future security risks. 

Also, according to the company, where 
other MSSPs are just providing managed 
appliances, ETSec evaluates relevant 
security risks, develops a formal security 
policy for its clients, and ensures and 
maintains regulatory compliance. 



Why navigate through countless Web sites when you can get all 
the information you need in just a few minutes by reading Processor! 
Processor's content is comprehensive, but it's presented in a 
quick, easy-to-read format, so you can keep up with the constant 
flood of new data center products and technologies. 
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Register at 

www.decparts.com 

for our monthly 
giveaway of an 
HP MIN1 1101 

'No purchase necessary 



• U.S. military-approved repair depot 

• Mission-critical supplier to NASA 

• VAX End of life fulfillment reseller Compaq Authorized 

• Key reactive response supplier to HP field service 
24/7 worldwide 

• 7000 skus and 2 million parts in inventory 

• Multimillion dollar test lab with printout diagnostics 
for each product supplied 



Free Repair Evaluation 



Call Toll Free: 888.332.7278 I In MA: 508.866.1171 I Visit us at www.decparts.com 



This is a small 
snapshot of the 
7,000 SKUs in stock 
LARGEST cable 
inventory worldwide: 

DISK & TAPE 
Part Number ....Price 

RD53-DA $895.00 

RD54-AA $995.00 

RZ29L-AA/VA $175.00 

RZ28-VA $145.00 

RZ1DD-SW/VW $60.00 

RZ28-VA $295.00 

TLZ09-VA $295.00 

TLZ10-VA $385.00 

TZ87/TZ88/TZ89 ....Starting at $125 

TSZ08-AA $1,995.00 

All VAX Parts & Spares 70% Off 
Compaq Preferred VAX Reseller 

DNPG Network 

DEZ8R-P $1,290.00 

DEFHIVl-IVllVl $5,800.00 

DEFEA-FB $1,275.00 

DSGGD-BA $1,500.00 

DZRVW Starting at $500 



All Compaq HP 
Blades 

Start at $595. OO 

DS10 $675.00 

DS20 Starting at $11 75 

GS80 $2,900.00 

GS160 Starting at $3,900 

GS320 Starting at $5,900 

RL01/RL02 Call 

RA60-P $475.00 New 

RA81 H.D.A $775.00 New 

RA82 H.D.A $775.00 New 

2T-48VDG $3,400.00 New 

VAX Systems & Options— Call 

Alphas Starting At 

ES40 $1,295.00 

ES45 $3,195.00 

ES47 $4,195.00 

Proliant Servers 
/ HP Blades 

AJ 742A $4,175.00 

AJ 753A $5,175.00 

Disks 

AJ 736A $535.00 

AJ 737A $825.00 

AJ 738A $385.00 

AJ 740A $675.00 



Memory 

413015-B21 $1,290.00 

397413-B21 $375.00 

HBA Fibre Channel 

AE311A $815.00 

A8003A $765.00 

LPE12000 $840.00 

Printers 

LA600/LN05/LN07/LA400/LN01/02 
/LN40 

Printer Repair 25% Off 



Full Depot 
Repair Facility 

OEC/Compaq/HP 
a" network products 

20% DISCOUNT 

TILL (lec25TH 
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Tighten Your Security Defenses 

staying one step ahead of cybercriminals 
can be overwhelming. We offer tips and 
strategies to help. 



Boost Your Security Arsenal 

30 

■ As hackers have become more 
sophisticated in their methods of 
malfeasance, so have tools that 
detect it. 



Rogue Access Points | 31 

■ Whether a rogue AP is accidental or 
malicious, it's a liability that should be 
handled immediately. 



Rooting Out Worms 
& Viruses | 32 

■ Developers of the most high- 
powered antiworm and antivirus tools 
that money can buy cannot always 
respond fast enough with updates that 
can block, locate, or eliminate the lat- 
est malware and keep it from contami- 
nating workstations and servers. 



Preventing Data Lealcs | 32 

■ You can stick your enterprise's data 
center into the equivalent of Fort 
Knox, but without a plan of action to 
contend with data leaks, you might as 
well toss your organization's intellectu- 
al coinage in the nearest dumpster. 



Boost Your Security Arsenal 

Having The Right Tools & Knowledge Can Help Prevent Security Breaches 



by Holly Dolezalek 

When it comes to security, the race 
often goes to the paranoid. Companies that 
effectively dodge, turn, and parry hacker 
attacks and employee lapses get to stay out 
of the headlines and don't have to face 
costly lawsuits. 

But paranoia works best when it's tem- 
pered with clear thinking, a sense of strate- 
gy, and attention to detail. That's why any 
consideration of beefing up security should 
start with a full understanding of what 
you're keeping secure. Before you go into 
the weeds to handle a specific threat or set 
of threats, stop and ask yourself: What am 
I protecting the company from? 

"All too often, potential clients want to 
fix a problem with a product," says Rocco 
Grillo, managing director at Protiviti 
(www.protiviti.com). "But before you can 
bolster your arsenal with tools, you need 
to go back to the basics. You need to 
know what are the root causes of security 
issues and come up with a robust security 
program based on those issues." 

Those root causes can come from an 
analysis of what you're actually protect- 
ing. Yes, it's your network, but get 
specific about what is in your network. Is 
it proprietary software or other intellec- 
tual property? Is it personal data? Is it 
credit card numbers? "Who am I, what 
do I have that someone would want, and 
what would someone want to do to me in 
order to make money or make a point?" 
says Fred Pinkett, vice president of prod- 
uct management for Core Security 
(www.coresecurity.com). The point is to 
make decisions based on what your com- 
pany is and what it's doing, not what the 
latest and greatest security technology is 
this week. 



Useful Tools 

There's no need to turn away from tools 
that can help you make your network not 
only more secure, but a new level of 
secure. As hackers have become more 
sophisticated in their methods of malfea- 
sance, so have tools that detect it. 

"The trend is toward network behavior 
analysis to detect not someone who is trying 
to penetrate the network, but someone who 
is trying to imitate an ordinary user's 
behavior, such as a hacker with several 
machines that are all trying to guess a user' s 
password," says Ron Meyran, director of 
product marketing for security products at 
Radware (www.radware.com). "These tools 
might detect, say, a higher number of level 
7 transactions without higher levels of rev- 
enue or the kind of attacks that are low-vol- 
ume and that can't be detected with analysis 
of traffic patterns." 

There are also tools to save work in an 
area that gets bigger the more security 
devices you have in place: log data. 
Firewalls, intrusion detection sys- 
tems, and other systems gener- 
ate volumes of log data, and 
not every company has the 
IT staff or know-how to 
benefit from it. "They're 
designed to provide 
better visibility into 
what's going on in 
your network," Mey- 
ran says. "It's not just 
seeing that a certain 
user was trying to 
penetrate the network 
through a particular 
route, but whether they 
succeeded or not and 
what needs to be done 



about it. It's a way to deal with that flood of 
log information and add another layer to 
your security posture." 

And if you thought the firewall is more 
or less a commodity now, think again. 
Firewalls have historically screened traffic 
by port, a designation that hackers stopped 
respecting a long time ago. Now, firewall 
makers are staking their claim on identify- 
ing incoming traffic by application, rather 
than by port, and on confirming that it's 
really a P2P or Web application session 
based on its layer 7 information rather than 
ports or protocols. 

Testing, Testing 

In any company, it can be hard for the 
right hand to know what the left hand is 
doing, and IT security involves dozens of 
hands. Security systems and applications 
are complex by themselves, and the way 



Key Points 



Before you buy or build anything to 
enhance your IT security, think about what 
you're protecting and why. 

Hackers are aiming for Web applications 
more these days because they're often less 
secure than the company's actual network. 

No security arsenal is complete unless it has 
been tested — attacked just like a hacker 
would attack it — ^to make sure it's providing 
the protection it's supposed to. 



Don't Forget Your Users 

The old triangle of people, processes, and technology applies to security just as it 
applies to any other IT function. Don't forget about people as you think about what is being 
protected, because users are often in a great position to accidentally expose or deliberately 
sabotage it. But it doesn't have to be all sticks and no carrots. If you can find a way to enlist and 
inspire users to be a part of the company's protection, all the better. 

"A former customer of mine couldn't lock down their PCs because of proprietary software they 
couldn't afford to upgrade," says Areyeh Goretsky, a researcher for ESET (www.eset.com). 'To 
encourage antivirus usage among employees, the administrator placed the EICAR test file (a 
harmless text file that antivirus programs report as a virus, used to verify that antivirus software is 
operating correctly) on some computers the night before and then announced that the first person 
to find a virus on their computer would receive a gift certificate for a local restaurant." 

Certainly, most environments are managed well enough that this kind of thing isn't necessary 
anymore. But it's a good example of finding a way to get employees to not only see but partici- 
pate in keeping the company network safe. 




they work with each other makes security 
a near-fractal business. It's harder in large 
environments than in small, Pinkett 
explains. "Smaller environments are more 
likely to have one person in charge of 
security, even if that person wears other 
hats, too," he says. "In larger environ- 
ments, someone might have responsibility 
for the firewall while someone else han- 
dles the antivirus application. A change in 
one area can affect something else, and 
what seems benign in one place can let a 



hacker get through in another. The same 
silos that cause problems across business 
cause problems in security." 

That means testing. Firewalls, antivirus 
applications, patches to existing systems: 
They should all be tested to make sure 
they're actually doing what they're sup- 
posed to be doing. "You've got to attack 
it yourself the way a hacker would, 
just as you would test a Web site 
to see if it's really working," 
Pinkett says. 

A Dissolving Perimeter 

E-commerce, contrac- 
tors, partners, VPNs — 
the historical boundary 
between a company 
and the rest of the 
world has been dis- 
solving for a long 
time. And one area of 
security in this area 
gets neglected all the 
time: Web applications. 
"If you look at the 
research, it shows that 
attacks are increasingly 
aimed at the Web applica- 
tion layer," says Georg Hess, 
CEO and co-founder of Art of 
Defence (www.artofdefence.com), 
a Web application security company 
in Regensburg, Germany. 
This is true whether companies use 
applications that were built in-house or 
third-party software, but at least third par- 
ties take responsibility for sending patches 
for application vulnerabilities. It may take 
six weeks at times, which is a long time to 
know you're vulnerable, but it beats the 
uncertainty of never knowing whether 
your own in-house application is riddled 
with holes that hackers are skipping 
through with delight. 

"Instead of trying to raise the bar where 
you're already at 90%, it makes sense to 
look at Web applications," Hess says. 
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News 



Rogue Access Points 



Find Suspicious Devices On Your Network 



by William Van Winkle 

The problem typically begins innocently 
enough. Some worker gets a new laptop 
with the latest wireless capabilities, only to 
find that the enterprise hasn't updated from 
old but reliable 802.1 Ig. So he grabs an 
extra wireless router or AP from home. 



Key Points 



Although a rogue access point can get 
hackers past a company's first line of 
defenses, it doesn't automatically grant 
access to servers and sensitive data. More 
common liabilities from rogue APs include 
loss of network bandwidth and available 
IP addresses. 

All access points and client devices should 
undergo some form of authentication 
before being allowed on the network. 

A wireless controller can offer a host 
of benefits to an enterprise WLAN, 
including the ability to quickly locate 
rogue APs through signal 
triangulation. 



plugs it into the nearest RJ-45 jack in 
the office, and — voila! Instant speed 
and productivity improvement. Of 
course, this unapproved device is also a 
gaping security hole. 

Not all "rogue" devices are so innocent. 
Peter Newton, director of SME product 
marketing for Netgear (www.netgear.com), 
tells of a hacker who modded a power strip, 
replacing its innards with those of an AP. 
Intruders had a wireless tunnel into the 
building via a device that was nearly impos- 
sible to detect visually. Whether a rogue AP 
is accidental or malicious, it's a liability that 
should be handled immediately. 

The Rogue Risk 

First, be aware that a rogue device 
doesn't automatically broadcast an enter- 
prise' s most prized data to anyone in 
reception range. If anything, it's a bit like 
plugging an electrical appliance into the 
wall. The AP may get juice (network 
access), but that doesn't mean it can auto- 
matically access servers or other systems, 
only that it's potentially been given an 
address on the LAN. 

"Most rogue APs are just something 
cheap, set by default to run as DHCP 
servers," says Jeanette Lee, senior systems 
engineer with Ruckus Wireless (www 
.ruckuswireless.com). "So when you plug 
these into a wired network, you run the 
chance that now you've got [a] rogue 
DHCP server giving out addresses. These 
will probably do nothing and go nowhere, 
but you never want two DHCP servers on 
the same network handing out addresses." 

Lee points out that many enterprises 
have authentication measures in place that 
prohibit rogue devices from siphoning 
bandwidth from the organization. But this 
doesn't apply to all networks. Some have 
to remain open to meet the needs of the 
enterprise. This yields a more common risk 
of having both rogue APs and clients con- 
suming IP addresses. 

"I'm dealing with a university here in 
southern California," she says, "where they 
average around 6,000 devices on their 



campus connected to their DHCP server. 
Well, when iPhones and gaming consoles 
and all that came out, they saw about 16,000 
addresses being consumed. They were actu- 
ally running out. Further investigation 
showed that most of these devices weren't 
doing anything — except having a negative 
impact on their network and resources." 

The real danger of rogue APs comes 
when network access protection isn't 
applied to LAN jacks at the desktop 
level, where rogues typically plug in. 
Methods such as 802. IX and encryption 
typically authenticate any connecting 
device, but many organizations omit such 




authentication so as not to hamper em- 
ployees. This freedom is what allows peo- 
ple to tap into networks from the parking 
lot. Usually, they just want a quick way 
onto the Web, but sometimes they could 
be up to something more nefarious. 

Rogue Remediation 

Not every rogue device on the LAN is an 
AP. Unauthorized client devices can pose 
just as large a threat. For many years, orga- 
nizations have used MAC filtering to keep 
out unwanted devices. The MAC address is 
the 48-bit ID address assigned to every net- 
work adapter. Admins can use MACs to 
create whitelists or blacklists. MAC filtering 
is simple and effective, but it works much 
better in a wired world than a wireless one. 

"Even on an encrypted connection," says 
Ruckus' Lee, "the MAC address is part of 
the IP frame header, which is not encrypted. 
So I can sit there with my machine, and 
even though I'm not on the network, I can 
see every packet that everyone else is trans- 
mitting. You might have encrypted the pay- 
load, but I can easily see your MAC address 
and change the address on my machine to 
copy it." 




Some wireless intrusion detection systems buiit into 
wireless controllers allow organizations to use floor 
plans overlaid witli access point locations. Witli these 
locations known, tl^e location of unauthorized access 
points can be quickly identified. (Source: Netgear) 



Some organizations will opt to use a 
"Web captive portal," or login page, to con- 
trol Web access. This is common at hotels 
and public hotspots and helps to keep peo- 
ple from stealing bandwidth. However, it 
won't keep devices from associating with 
the network like encryption would. 

Another option, according to Nimesh 
Vakharia, senior product manager at 
Symantec (www.symantec.com), is to use 
a dynamic preshared key. With this, every 
authorized client that connects to the net- 
work is given a unique preshared key that 
must be presented to the network to asso- 
ciate with it. Authorized devices that pre- 
sent a proper key will be given an IP 
address; other devices will be denied. This 
approach takes more planning than an 
open network, but it has advantages over 
conventional encryption, including not 
necessitating a performance hit for 
encryption overhead. 

Vakharia also advocates a quaran- 
tine system for newly associated 
systems. This addresses the problem 
of approved devices bringing risks 
into the network. "When a contrac- 
tor comes in," he says, "there's no 
way to control what's on his system, 
but you can force him to be compliant 
with your policies. Does he have 
antivirus? Is it updated? Does he have 
firewall? Does he have the OS patches? 
Once you've validated all that, then you 
allow him on the network." 

With this method, as soon as a new 
device comes on the network, it gets placed 
in a quarantined VLAN with no network 
access. The device only has access to a 
remediation server, and not until the device 
passes safety checks is it allowed out of 
quarantine and onto the regular network. 
This quarantine work can either be run from 
an appliance or, for lower volume needs, 
from an app running on a server. Often, it 
requires an agent to be installed on the client 
device, but these can "dissolve" and leave 
no trace of themselves (save a fully patched 
configuration) once the device logs off. 

Both Lee and Newton reiterate the impor- 
tance of using a wireless controller, particu- 
larly in medium-sized and large organiza- 
tions. "A wireless controller gives you a 
whole host of benefits," says Newton, 
"including centralized management, a self- 
healing wireless network that makes sure all 
users stay connected, load balancing, trans- 
mit power adjustment, etc. One benefit of 
the wireless controller is that it can provide 
triangulation data. Because it's receiving 
information from multiple APs, it can find a 
rogue AP out there and tell you where it is." 

This triangulation is generally accurate 
to within a few feet. Use it to locate the 
rogue device, pull it off the network, and 
find out who put it in action. (Without a 
wireless controller, IT staff can use wire- 
less scanning software on a notebook to 
perform a survey for unauthorized de- 
vices.) IT may want to lecture about com- 
pany policy, but often the rogue AP was 
placed for a valid reason. 

"It's always [better] to unplug a rogue AP 
and throw [it] in the trash than it is to do 
some kind of intangible containment," says 
Ruckus' Lee. "But find out who put it there. 
If you listen, workers will educate you that 
something needs to be addressed on the 
wireless network." 



I Nol(ia Accuses Apple 
Of Patent Infringement 

Nokia has filed a complaint against Apple 
with the U.S. International Trade Commission 
alleging that Apple is abusing Nokia-held 
patents concerning interface, camera, anten- 
na, and power management technologies in 
a large number of Apple's mobile phones, 




portable music players, and computers. 
Nokia originally sued Apple in October of last 
year over 10 wireless handset patents. Apple 
retaliated with a suit against Nokia in Decem- 
ber, claiming that Nokia also infringed on 
13 iPhone patents. The ITC is investigating 
unfair patent trade practices involving trade- 
mark and copyright infringement. 

I IDC: PC Shipments To Increase 

According to a recent study from IDC, PC 
shipments worldwide will grow by double 
digits on a yearly basis through 2010. IDC 
found that growing demand for portable com- 
puters, such as notebooks and netbooks, and 
increased commercial spending will fuel the 
market's growth. Another contributing factor 
is that computer shipments decreased or 
remained flat in the last three quarters of 
2009. In total, 2009 saw 291.4 million com- 
puters shipped worldwide, and IDC estimates 
that the number could reach 321 .4 million by 
the end of this year. Futhermore, IDC indi- 
cates that by 2013, shipments could reach 
444.4 million units. 




I Genband Leads Offers 
On Nortel's VoIP Assets 

Nortel has announced that it will sell its 
Carrier VoIP and Application Solutions 
business to Genband, a supplier of IP 
gateways and FMC security solutions. 
The stalking horse agreement states that 
Genband will buy Nortel for $282 million, 
though companies can still bid on Nortel's 
assets in an upcoming auction. Genband 
CEO Charlie Vogt says that Genband would 
pair its gateway portfolio with Nortel's carri- 
er VoIP and Softswitch expertise and that 
the two companies are a good fit thanks to 
a pre-existing relationship. 

I China Mobile Exec 
Under Investigation 

China Mobile Executive Director and Vice 
Chairman Zhang Chunjiang, head of the 
Communist Party council at China Mobile's 
parent company, is being investigated by 
Chinese authorities for "serious personal 
violations." Details on the violations were not 
released, although later reports confirm that 
Chunjiang was dismissed from his role as 
party secretary and vice president but not 
yet from his position as vice chairman or 
executive director of China Mobile's Hong 
Kong unit; China Mobile is suggesting fur- 
ther dismissal. 
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Rooting Out 
Worms & Viruses 



Combine Smart Tactics With The Right Tools 



by Bruce Gain 

Developers of the most high-powered 
antiworm and antivirus tools that money 
can buy cannot always respond fast enough 
with updates that can block, locate, or elim- 
inate the latest malware and keep it from 
contaminating workstations and servers. 
Preventing worms, viruses, and other rogue 
programs from doing damage thus requires 
more than just installing software and wait- 
ing for the alerts to come. Instead, malware 
security should also involve skill and savvy 
on the part of the admin. 

Here are some tips, strategies, and advice 
on how to help eliminate the malware 
scourge, as well as what to look for when 
seeking out the best software tools. 

Be Aggressive 

In today's threat environment, simply 
ensuring that all machines have the latest 
security patches is not enough; instead, 
SMEs should dedicate at least one person 
on staff to proactively and routinely monitor 
and probe the network by using monitoring 
tools to seek out network abnormalities 
instead of waiting for the alerts. 

According to Brian Grayek, vice president 
of product management for CA's Internet 



Key Points 



At least one staffer should be actively and 
aggressively monitoring network traffic to 
check for problems, even before receiving 
alerts from anti-malware software if possible. 

Make sure that suspected files are indeed 
malware first and then analyze the files 
closely before deleting them. 

Robust anti-malware must be easy to 
deploy and use, be able to work on a 
network level, and not negatively affect 
network performance once installed. 



Security business unit (www.ca.com), when 
it comes to malware, the best defense is a 
good offense. "For many rootkits, they can 
remain almost completely silent and the 
only way to find them is to discover anom- 
alous network activity that can lead to an 
infected workstation." 

When there is an alert and you have locat- 
ed the rogue program, it is also a good idea 
to go one step further by making sure that 
your monitoring tool did what it was sup- 
posed to do. "Check that any alerts in the 
IDS/IPS are consistent with the malware type 



you think it is and 
make sure no other 
machines are affect- 
ed, which may not 
have come to your 
attention," says Jamie 
Riden, a member of 
the UK Honeynet Pro- 
ject (www.honeynet.org) 
and an independent securi 
ty researcher. 

Quarantine, Then Delete 

A rogue executable file is detect 
ed. Do you quarantine or delete it? The 
reaction of many novice admins would be 
the latter. However, even the most high- 
powered security software can flag false 
positives, which means clicking the delete 
option could cause you to remove files 
you actually need. 

"Every major anti-malware vendor today 
has and will continue to experience false 
positives, where the anti-malware product 
has falsely identified a 'clean' file (an appli- 
cation or even the operating system) as an 
infected file. This is occurring more often as 
generic detections are used to detect the 
majority of variants that are produced 
today," Grayek says. "If a false positive 




does occur and the system still contains the 
quarantined 'clean' file, then it is quite an 
easy repair to replace the quarantined file 
back into the computer." 

However, if you have deleted all the mal- 
ware files, then most of the work will 
involve locating and replacing the removed 
file in all the affected computer systems, 
Grayek says. "This can be quite an exten- 
sive operation if the company affected is 
like most, which maintain a heterogeneous 
environment of mixed operating systems 
and application revisions," he says. 



Preventing 
Data Leaks 

A Dose Of Security Savvy Will Help 
Plug The Cracks In Your Data Center 



by Robyn Weisman 

You can stick your enterprise's data cen- 
ter into the equivalent of Fort Knox, but 
without a plan of action to contend with 
data leaks, you might as well toss your 
organization's intellectual coinage in the 
nearest dumpster. And seemingly any strat- 
egy you put in place has to take so many 
variables into account — from careless sales 
staff leaving their data-laden smartphones 
at an airport bar to the equally cliched (but 
worrisome) third-world hacker worming 
his way into your network via various 
phishing techniques. 

"Data leakage has been one of the top 
headlines in the IT world for 2009," says 
Chet Wisniewski, senior security advisor 
at security solutions provider Sophos 
(www.sophos.com). "Most organizations 
have recognized the need to protect 
[portable devices such as laptops, thumb 
drives, and smartphones] against theft and 



compromise using full disk encryption, but 
there is much more an administrator can do 
to ensure their business is protected." 

So what should you keep in mind when 
devising a coherent data protection plan? 
Here is a look at some expert advice on 
how to properly keep your data in check 
and safe — and out of the news. 

Go To The End Points 

The first step to preventing data leaks is to 
simplify and centralize the control and man- 
agement of your data end points, says David 
Ferre, senior product manager of endpoint 
security at Novell (www.novell.com). Ferre 
suggests a policy-based approach to system- 
atically prevent data leaks before they can 
take place, stressing three key areas: remov- 
able storage devices, wireless security, and 
data encryption. 

Security policies for removable storage 
devices such as USB-enabled and other 
mobile devices put an audit trail in place so 



Key Points 



• Put unified endpoint security policies 
in place. 

• Data encryption is a must to protect data 
in motion. 

• Install a secure communications perimeter 
around your internal network. 



that users who copy large amounts of cor- 
porate data may be tracked. Moreover, they 
can prevent users from accessing enterprise 
data from devices that haven't been autho- 
rized for use by your organization, which 
helps to decrease the risk of viruses and 
malicious software being introduced into 
your network, Ferre says. 

Similarly, wireless security policies con- 
trol which users can connect to your net- 
work via the Internet as well as where and 
when they can connect. "With wireless 
security policies in place, IT administrators 
can ensure users access only approved 
Internet connections and prevent hackers 
from accessing corporate data through 
unsecured wireless access points at air- 
ports, coffee shops, or other similar loca- 
tions," Ferre says. 

Protecting Data In l\/lotion 

A comprehensive file and full disk data 
encryption scheme protects your data while 
it is on the move and is most prone to being 
stolen or misplaced. Moreover, data 
encryption policies help to keep your data 
compliant with regulations such as PCI 



DSS (Payment Card Industry Data Security 
Standard) and HIPAA, says Ferre. 

For his part, Sophos' Wisniewski says 
that file-level encryption is especially 
important given that many organizations are 
seeing data stolen directly from compro- 
mised desktops or servers within the data 
center. "Encrypting that data directly on file 
shares can help prevent hijacked data from 
being of use to the attacker," he says. 

Wisniewski says that controlling the 
movement of what he calls "data in 
motion" also is key both for protecting data 
and for refining your overall data protec- 
tion policy. "Most companies do not have 
good visibility into where much of their 
sensitive data is or where it has been 
going," he says. "By using a desktop data 
leakage prevention product, you can see 
who is accessing sensitive information and 
where that information resides." 

Limit The Applications 
Accessing Your Data 

It isn't enough, however, to simply 
encrypt your data if your employees are 
able to decrypt said data and use it on any 
application. Wisniewski says that limiting 
the types of applications they can use will 
save you a lot of grief in keeping your 
data safe. 

"The Department of Defense had to 
acknowledge that secret blueprints for sen- 
sitive aircrafts were recently leaked onto 
peer-to-peer networking sites," he says. 
"Controlling the use of peer-to-peer and 
other unwanted applications in the enter- 
prise goes a long way in stopping the leak- 
age at the source." 
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Study The Threat 

It is often scary when malware 
is detected, especially when it 
is a more dangerous variant 
that could have done 
some real harm. But 
before deleting the 
scourge forever, 
now is the time to 
analyze both the 
rogue program 
and the infected 
machine. 

The first thing 
to do is to re- 
move the infected 
machine from the 
network while re- 
storing a replace- 
ment with a re- 
imaged one from a 
backup, Riden says. 
"You can poke about at 
your leisure," he says. 
"You may need to do this if 
it's a new piece of malware 
that has affected several machines 
at your workplace and is not yet dealt 
with by your [anti-malware] solution." 
Googling the malware for more infor- 
mation does not hurt, and it is also a good 
idea to use software that can analyze the 
rogue file or files, Riden says. "[Proving 
malware with software] should give you 
some sort of handle on what it' s doing," he 
says. "This will allow you to do network 
remediation with IDS/IPS to contain the 
malware as much as possible. Also, submit 
it to your antivirus vendor if you haven't 
already got coverage." 

Find The Right Power Tools 

In addition to aggressive hands-on tactics, 
you still need the right software tools to get 




Stop Steganography 

Steganography, the practice of encoding 
sensitive information inside innocuous files, 
is more widespread tinan you might believe. 
Jim Wingate, vice president at Backbone 
Security (www.backbonesecurity.com) and 
director of its Steganography Analysis and 
Research Center (or SARC; www.sarc-wv 
.com), says that steganography applications 
are easily available via the Web and require 
little tech savvy to use. 

Wingate points out that people attempting 
to steal information from within an organiza- 
tion are trying to do so without getting 
caught, and as more companies become 
savvy to encryption and other data protec- 
tion strategies, some percentage of these 
malefactors land upon steganography as an 
effective way to avoid getting caught. And if 
you're not actively monitoring for it, don't 
expect those using it to wave their hands 
and spell out what they're doing, he says. 
(For more information on this topic, see 
"Steganalysis Experts" on page 27.) 



Secure The Servers 

No matter how well you patrol end 
points, enforce security using encryption 
methods and control the ways in which 
applications on your network can access 
your data, leaks will still occur on the 
servers themselves, says K. Scott Morrison, 
CTO at security vendor Layer 7 Technol- 
ogies (www.layer7tech.com). 



"Check that any alerts in the IDS/IPS are 
consistent with the malware type you 
think it is and make sure no other 
machines are affected, which may not 
have come to your attention." 

- The UK Honeynet Project's Jamie Riden 



the job done of detecting and removing mal- 
ware. When seeking out the best tools, 
determine whether it can be easily managed 
and monitored, its potential impact on sys- 
tem performance, and its ease of deploy- 
ment, says John Matzek, co-CEO of Logic 
IT Consulting (www.logicitc.com). 

It is also important to make sure that 
anti-malware can do what it is supposed to 
do on a network level. For example, 
Matzek says it is possible to add a tool at 



the edge of your network that cleans virus- 
es from your HTTP or SMTP traffic. "This 
will prevent a virus from even getting into 
or out of your network through email or 
Web traffic," he says. 

"Other software allows you to scan the 
network and look for all hosts that do not 
already have antivirus installed," Matzek 
says. "Then, of course, you can deploy 
antivirus from the server without having to 
log in to each host." Q 



One Machine Is All It Takes: 
Keep Updates Current 



A single infected machine is enough to give a Trojan or a worm an opportunity to do its damage on a 
network. Whether it is a laptop that someone uses from a remote office or a desktop workstation at the 
enterprise's headquarters, all machines must install the updates as soon as they become available. 

"Verify that every workstation is receiving and applying the latest operating system patches, as 
93% of all malware infections we find come from companies that 'believe' that all workstations 
are receiving auto-updates," says Brian Grayek, vice president of product management for CA's 
Internet Security business unit (www.ca.com). "All it takes is just one open computer to bring down 
an entire company. [Additionally,] every computer should be verified to be running the company's 
selected anti-malware solution and that they have received the latest signature update." 




Morrison rec- 
ommends counteract 
ing server-level data leakage 
by implementing redaction gateways. "You 
set up a secure communications perimeter 
surrounding your internal network that 
inspects all data going outside the network 
for information that should not be allowed 
outside," he explains. "If it finds anything, 
it can either stop the transaction entirely or 
remove the data in question — like the clas- 
sic black marker redaction on a document." 

According to Morrison, the concept is 
simple, although you do need fairly 



sophisticated 
querying capabilities 
to distinguish what consti- 
tutes a leak. "Customers can set up scans 
for certain key words and patterns that 
should be redacted if they appear in a 
communications stream, whether it origi- 
nates inside the organization or is a reply 
to a request originating outside the orga- 
nization," Morrison says, adding that 
there have been several government 
deployments of this type of technology to 
protect classified data from leaking out- 
side the internal network. 




I Stimulus Money To Help Fund 
Health IT Research 

The U.S. Department of Health and Human 
Services announced that $60 million of fed- 
eral stimulus money will be offered to orga- 
nizations striving to break through the barri- 
ers surrounding IT in the health industry. 
The SHARP (Strategic Health IT Advanced 
Research Projects) program aims to reduce 
security and privacy risks, develop trust in 
health IT, refine network platform architec- 
tures for the electronic exchange of health 
information, and improve the quality of 
health care overall. The research will take 
place over a period of four years with aspi- 
rations of a meaningful healthcare system 
for all Americans. 

I Report Examines Emerging Tech 
Markets For Government 

Cloud computing, virtualization, and open- 
source software are expected to make big 
gains in the state and local government 
arena, with cost-cutting sen/ing as the driving 
force behind adoption of these technologies. 
According to market research firm Input, state 
and local government spending on cloud 
computing will grow from $230 million last 
year to $620 million by 2014, showing a com- 
pound annual growth rate of 22%. PaaS 
(platform as a service) and SaaS are expect- 
ed to see the largest growth. Input expects 
the virtualization market to grow from $360 
million in 2009 to $580 million by 2014— a 
CAGR of 10%. The open-source software 
market is expected to grow at 1 1 % CAGR, 
from $160 million to $280 million. 

I Google Still Dominates 
Search Market 

Google and Microsoft posted gains in the 
market for search engine dominance, and 
Yahoo! posted a slight loss. ComScore's 
November monthly search engine report 
shows that Americans conducted 14.4 billion 
searches during the month. Google was used 
for 65.6% of those searches — a 0.2% gain 
from the previous month. Yahoo! accounted 
for 1 7.5% of searches, down 0.5% from 
October, and IVIicrosoft sites accounted for 
10.3% of searches, up 0.4%. In November 
2008, Google had a 63.5% share of the mar- 
ket, followed by Yahoo! with 20.4% and 
Microsoft sites with 8.3%. 

I Google's Buyout Of AdMob Opposed 

Two consumer groups have asked the 
Federal Trade Commission to block Google's 
$750 million acquisition of mobile advertising 
company AdMob. Consumer Watchdog and 
the Center for Digital Democracy say the deal 
would hurt consumers by hampering competi- 
tion in the growing mobile advertising market. 
The groups also argue that information the 
companies collect about consumers' online 
behavior could threaten user privacy. The 
request came a week after the FTC asked 
Google for more information about the deal, 
which was announced last month. A Google 
spokesman said the acquisition poses no 
threat to competition within the mobile adver- 
tising market and that two of Google's main 
rivals, Microsoft and Yahoo!, have made simi- 
lar purchases in the past two years. 
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MESSAGING & TELEPHONY 



Telecom Expense 
Management 



TEM Software & Services Can Bring Order 
& Savings To Your Telecom Finances 



by Kurt Marko 

Telecommunications networks may 
be the lifeblood of the modern enterprise, 
but they're clogged with cholesterol in 
the form of byzantine, complex, and 
often inscrutable bills. As enterprises 
have increased their use of telecom ser- 
vices, the monthly invoices — which 
often come from a host of different 
voice, data, and wireless carriers 
throughout the country — are so ponder- 
ous they make hospital bills look trivial 
by comparison. 

Telecom expenses often account for up 
to 20% of an enterprise's entire IT budget, 
according to Forrester Research Principal 
Analyst Phil Sayer. Put another way, 
telecom spending can equal 1 to 2% of a 
company's revenue, says Tangoe Market- 
ing Director Jacques Wagemaker (www 
.tangoe.com). 

No matter how you slice it, telecom is a 
significant expense. With the complexity 
of telecom billing worsening as firms add 
mobile devices, wireless services, and new 
data circuits, the overhead in handling 
the monthly paperwork is significant. 
Kathleen Glass, vice president of market- 
ing at ProfitLine (www.profitline.com), 
estimates the typical IT department needs 
one full-time employee to manage billing 
for every $2 million to $5 million in tele- 
com spending, which translates into one 
dedicated overhead position for a $100 
million company. 

This is a problem tailor-made for an 
automated solution, which the experts dub 
TEM (Telecom Expense Management). 

TEM Delivery Models 

TEM solutions originated as dedicated 
software platforms deployed inside large 
enterprises to consolidate telecom in- 
voices, document circuit inventory, and 
audit for billing errors, says Glass. This 



Key Points 



TEM (Telecom Expense Management) can 
consolidate hundreds of carrier Invoices for 
everything from voice and data circuits to 
wireless phones into a manageable data- 
base that facilitates efficient payment pro- 
cessing, audits for billing accuracy, and 
consumption tracking. 

Originally delivered as a packaged 
software product operated by individual 
IT departments, TEM solutions are 
now available as SaaS offerings or 
wholly outsourced managed business 
process sen/ices. 

TEM solutions are generally suitable for 
organizations with telecom spending 
exceeding $1 million annually and 
promise savings of 1 0% or more of the 
annual budget. 



provides a single point of expense 
approval and payment, tracks usage, and 
facilitates IT chargeback billing. Like so 
many other software solutions, TEM has 
subsequently entered the cloud and is 
increasingly delivered as a managed appli- 
cation operated by a service provider and 
administered by internal IT (SaaS). The 
market has also evolved an ecosystem of 
BPOs (business process outsourcers), 
which specialize in telecom management 
that administers SaaS solutions on behalf 
of an enterprise, thus overloading the 
entire workload from overstretched enter- 
prise IT departments. 

From its genesis in invoice consolida- 
tion, which usually includes invoice pay- 
ment processing, and asset management, 
which tracks purchases (both circuits and 
devices), contracts, and leases. Glass says 
TEM solutions have grown to address the 
complete telecom service life cycle, from 
vendor sourcing and service provisioning 



to invoice validation and payment. TEM 
products also produce extensive finan- 
cial, business, and technical reports on all 
elements of telecom infrastructure, ana- 
lytic features that improve spending fore- 
casts, and vendor pricing comparisons. 
According to a Gartner study, these are 
becoming key differentiators among 
TEM vendors. 

Many products have added support for 
the myriad wireless devices and services 
now deployed in the enterprise — what 
Glass terms WEM (Wireless Expense 
Management). Wagemaker says compre- 
hensive and lifecycle TEM features 
include evaluating and comparing new 
products and services, ordering and pro- 
visioning, contract management, usage 
tracking and reporting, rate optimization, 
and dispute management (identifying 
billing errors or service credits and facil- 
itating charge recovery). 

With such a plethora of telecom carriers 
and service providers throughout the coun- 
try and around the world, a key considera- 
tion when evaluating any TEM solution, 
according to Sager, is ensuring support for 
a company's particular mix of carriers and 
services. And there are no standards for 
electronic exchange of invoices, so Glass 
stresses the importance of broad carrier 
support and ease of data integration, 
adding that any TEM solution "must be 
carrier agnostic." 

As part of the evaluation process, 
Wagemaker advises buyers to determine 
whether they want to own and operate 
their own solution, run a SaaS offering, or 
completely outsource to a managed ser- 
vices provider. Next, he says buyers need 
to outline the scope of their requirements 
and decide whether they just need invoice 
consolidation and processing or telecom 
lifecycle management and also whether 
mobile device management should be part 
of the mix. 



Financial Benefits 

Many enterprises get hundreds of tele- 
com bills for various services with differ- 
ent tariffs and rate structures. "It's an 
impossible task to check all that manual- 
ly," says Sager. Given the complexity of 
telecom invoices, it's not surprising that 
upward of 80% contain errors, usually in 
favor of the carrier, which Sager says can 
result in overbilling of 5% or more. Thus, 
he estimates the typical savings for new 
TEM installations are at least 10% and 
often closer to 20%. In addition to increas- 
ing statement and billing accuracy, Sager 
says TEM's auditing features can identify 
under- or un-used circuits that could be 
decommissioned to further reduce costs. 

With many TEM products targeted to 
SMEs, along with the availability of man- 
aged service providers and SaaS delivery 
options, "you don't have to be a huge 
multinational enterprise to use TEM," says 
Sager, adding that organizations with tele- 
com spending of $1 million or more will 
likely see benefits. 

Despite the benefits and relative maturi- 
ty of the traditional TEM invoice manage- 
ment products. Glass says outside of large 
enterprises, TEM solutions aren't widely 
deployed. Sager characterizes the TEM 
market as coming of age and sees increas- 
ing specialization from niche players 
focusing on medium-sized enterprises, 
thus expanding the options for SMEs. u 

TEM Market 
Segmentation 
& Feature Sets 

TEM solutions can be delivered in one of 
three ways: as licensed and hosted applica- 
tions, a managed application sen/ice (SaaS), 
or completely outsourced to a BPO 
(Business Process Outsourcer). 

The heart of any TEM solution is an auto- 
mated software platform that manages a 
company's telecom invoices and assets. 
The most common features include: 

• Sourcing management 

• Ordering and provisioning 

• Inventory and asset management 

• Invoice management and processing 

• Usage management and tracking 

• Vendor dispute management 

• Reporting and business intelligence 
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MESSAGING & TELEPHONY 



Email In The Cloud: 
Is It The Right Choice? 

Know The Requirements, Advantages & Challenges Before Making The Move 



by Carmen Carmack 

If you want to move some of your IT 
load to the cloud, email is a natural candi- 
date for consideration. Email is a cost of 
doing business that can require a large 
investment in staff and budget. Cloud- 
based email offers enterprises a number of 
advantages, and it can be more cost-effec- 
tive than maintaining an in-house solution. 
Because email is a mission-critical appli- 
cation, you should carefully consider the 
business requirements, advantages, and 
challenges related to the cloud. 

Requirements 

Before you move email to the cloud, 
you should identify your business require- 
ments. This includes but is not limited to 
whether you need collaboration capabili- 
ties, customization and integration solu- 
tions, and mobile support. 

"One should first consider what I would 
call the class of the email service," says 
James Bond, director of engineering at 
Apptix (www.apptix.com). "Do you need 
a full collaboration system that com- 
bines email, calendaring, contacts, and 
complete sharing within your organi- 
zation?" A Microsoft Exchange-based 
system, for example, offers more collabo- 
ration capabilities than Web-only or POP- 
based email systems. 

Migration 
Tecliniques 

Migrating your current email application to a 
new environment is challenging. James 
Bond, director of engineering at Apptix 
(www.apptix.com), suggests two possible 
methods for making the switch. 

'The instant cutover technique involves pre- 
creating all the mailboxes in the new provider, 
and then going live over a weekend. During 
that same weekend, your legacy data will be 
transmitted or physically shipped to the new 
provider, and [that provider] will backfill your 
data into your new mailbox," says Bond. 
Often, this type of migration is the least 
painful and disruptive to users and also least 
costly (free from some providers). 

The longer-term method involves pre-creat- 
ing the new mailboxes and then running 
synchronization tools in the background that 
send all data to the new service over a peri- 
od of days or weeks. "Both the old and new 
mailbox will be in sync at all times so that 
groups of users can be cutover whenever 
convenient," says Bond. Users that have not 
been migrated continue to use the legacy 
mail system and do not even realize that 
some users are already on the new email 
system. This coexistence of the two email 
systems is often more expensive and time- 
consuming to configure, but it is as seam- 
less as possible for end users during the 
cutover process. 



I Shahab Kaviani, vice president of sales 
and marketing at HyperOffice (www 
.hyperoffice.com), suggests that with 
today's email overload problems, enter- 
prises should look at moving things out 
of email and into tools that are better 
suited for the task. For example, instead 
of setting appointments via email, use a 
collaboration system with a group calen- 
dar, suggests Kaviani. 

Your functional requirements are 
another consideration. "Are you comfort- 
able with a generic, out-of-the-box, 
turnkey solution?" asks Patrick Verho- 
even, senior manager of IT solutions/ 
product management at Verizon. SaaS 
solutions work well because you don't 
have to build up an infrastructure. It's 
a turnkey solution with a predictable 
price, he says. 

"But what we're seeing is that those 
types of solutions do come with some 
constraints and limitations," Verhoeven 
says. A larger enterprise typically has 
complex needs around integration and 
customization, which may require a ded- 
icated messaging environment. This can 
be an Exchange or Lotus Notes environ- 
ment, where all of the infrastructure, 
applications, and services are dedicated to 
that single customer, says Verhoeven. 

Mobility is a critical feature and an 
advantage of cloud-based email. "You'll 
want to find out if the providers you 
work with can handle push email cost- 
effectively and whether they can support 
multiple devices and mobile operating 
systems," says Kaviani. And if you are 
using mobile email, you probably need to 
sync your contacts and calendar. "I would 
want to know if the provider can do that 
and at what cost. A lot of them can do 
over-the-air syncing, but at a hefty price," 
says Kaviani. 

Advantages Of The Cloud 

Cloud-based email offers enterprises a 
number of advantages, including better allo- 
cation of resources, potential cost reduc- 
tions, and enhanced security and reliability. 
"At the end of the day, your mail envi- 

I ronment is not what's going to differ- 
entiate your business in your vertical 
industry," says Verhoeven. Email is ideal 

I for outsourcing because it lets you take 
your limited resources and focus them 
on the applications that differentiate your 
business. "Does it really make sense, for 
example, to hire and train staff to build 
out an MS Exchange environment?" 
asks Verhoeven. "You need expertise 

I around storage, networking. Exchange, 
and Active Directory administration — 
so you're talking about a fairly complex 

I and expensive team of resources to sup- 
port this environment." 

Hosted services are now mature enough 
that they are actually less costly than 
building, maintaining, and upgrading in- 
house systems — not to mention the cost 
of IT personnel to install and operate 
everything, says Bond. The more mature 
cloud-based email providers go well 



beyond email services, also providing 
intranet/team Web sites, file sharing, 
group calendaring, instant messaging, 
VoIP, remote desktop, Web conferencing, 
and Web site hosting — all at a lower cost 



Key Points 



• Before you move email to the cloud, 
you should identify your business 
requirements. 

• Email is ideal for outsourcing because 
it lets you take your limited resources 
and focus them on the applications that 
differentiate your enterprise. 

• IVIigration from your current email 
application to a cloud-based solution 
is one of the most important consid- 
erations during the evaluation and 
planning processes. 



than organizations that deploy them in- 
house, he says. 

"Most organizations today simply don't 
understand what it truly costs to deliver a 
mailbox," says Verhoeven. "Many cus- 
tomers find themselves with limited capi- 
tal budgets, so they don't have the capital 
needed to build out and maintain these 
systems. Through a service provider, you 
can achieve the level of predictably that 
you cannot obtain internally." 

With the volume of spam and types of 
threats in the IT environment today, 
security is a growing challenge. "Hosted 
systems alone block over 80% of the 
incoming emails without even having to 
scan the message. These are multimil- 
lion-dollar data centers and antispam/ 
antivirus services that are capable of 
handling anything the Internet has to 
throw at it," says Bond. This alone saves 



enterprises bandwidth, reduces security 
threats, and reduces the costs of running 
your own system. 

Bond also says that hosted systems are 
online longer and experience fewer produc- 
tivity interruptions than most in-house 
email systems, because email providers 
have massive server clusters and network 
failover. "Plus, they hire nothing but email 
experts to keep things running, so providers 
are much more adept at maintaining the 
systems and keeping as close to 100% 
availability as possible," he says. 

Challenges 

While cloud-based email offers numer- 
ous advantages, making the move to the 
cloud is likely the biggest challenge. 



Accounting for interoperability needs with 
your current applications and the per- 
ceived loss of control are additional chal- 
lenges to address. 

Migration is one of the most important 
considerations during the evaluation and 
planning processes. "Do you plan on 
migrating all your users to the new cloud- 
based email system at one time, or do you 
have so many users that you must stagger 
the migration over several weeks or 
months?" asks Bond. Your chosen email 
provider should be able to give you both 
options and describe how it would handle 
your situation. 

Another consideration is pointing your 
DNS MX records at your hosting provider 
to the new service, says Kaviani. "Where 
I've seen that become problematic is 
sometimes the hosting provider and the 
new mail service provider are not com- 
municating or don't set the configuration 
correctly on the MX record switch." 
You also need to think about how you get 
the existing mail and information over to 
the new system. "What sort of turnkey 
migration tools do you have that can bring 
all of the Outlook or other mail data 
over?" asks Kaviani. 

Some organizations need an email solu- 
tion that works with their user provision- 
ing and application systems. "A lot of our 
larger enterprises want to integrate their 
mail environment with their corporate 
Active Directory domain[s] for single 
sign-on and seamless provisioning," says 
Verhoeven. "They also want to inte- 
grate with third-party applications, such 
as approval and workflow processes." 
And they may have very specific policy 
requirements around mailbox sizes, mes- 
sage sizes, and forwarding rules. With 
these requirements, he says, the orga- 
nization probably needs a dedicated 



cloud-based environment instead of a 
shared cloud-based email solution. 

"One perceived con about hosting email 
in the cloud is the supposed loss of con- 
trol of important data and systems," says 
Bond. "The reality is that these systems 
are going to be online longer — less down- 
time — and experience fewer productivity 
interruptions than most in-house email 
systems, simply because your email 
provider has massive server clusters and 
network failover to keep things working 
and online." As for losing control, email 
providers typically offer a Web-based 
administrative control panel, giving all of 
the email system functionality and self- 
administration capabilities back to their 
customers, says Bond. 



Cloud-based email offers enterprises 
a number of advantages, and it 
can be more cost-effective than 
maintaining an in-house solution. 
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IT Spending Up, 
Jobs Mostly Static 
For 2010 

The IT industry will see a measure of recov- 
ery in the coming year, according to a new 
study. In "IDC Predictions 2010: Recovery 
and Transformation," IDC Chief Analyst 
Frank Gens says that this year he expects to 
see dramatic growth in emerging markets, 
cloud services, mobile devices and applica- 
tions, and high-speed networks. 

The research firm also expects IT decision 
makers to loosen the purse strings a bit this 
year, saying consumers and businesses 
worldwide will increase their telecommunica- 
tions, hardware, software, and services bud- 
gets by 3.2% compared to last year, which 
will bring industry revenues to 2008 levels of 
about $1 .5 trillion. More than 50% of the IT 
industry growth will occur in Brazil, Russia, 
India, and China, where spending will in- 
crease between 8 and 13%. IDC also points 
to the smartphone's increasing popularity and 
the rumored arrival of Apple's tablet PC as 
two factors that will result in 1 billion mobile 
devices accessing the Internet by the end of 
this year. IDC also expects to see a tripling of 
iPhone apps, a quintupling of Android apps, 
and a similar boom for netbook-based apps. 

Impressive Gains 

Gartner agrees that worldwide IT spending 
will see impressive gains in the coming year. 
The firm's "Worldwide IT Spending Forecast" 
shows an expected 3.3% increase in IT 
spending compared to 2009 levels. Gartner 
reports that U.S. IT spending for this year will 
reach $958 billion, which is just slightly better 
than 2008's $957 billion spending and a good 
deal better than last year's $932 billion. 
Gartner pegs total hardware spending for 
201 at 2009 levels, or $31 7 billion. Gartner 
thinks the real upswing will occur in software, 
reporting that $231 billion will be spent in 
2010 compared to 2008's $225 billion and 
2009's $221 billion. 

But jobs are where the IT industry contin- 
ues to suffer, and the IT job placement firms 
Robert Half Technology and Foote Partners 
have only tepid news on the jobs front. A 
recent Foote Partners survey predicts that 
meaningful IT jobs growth won't occur until 
201 1 . Robert Half expects some growth in 
technology jobs overall, with greatest 
prospects for IT personnel in security, busi- 
ness intelligence, and SAP. The Foote 
Partners sun/ey reports that IT jobs in the 
biggest demand include security and SAP, 
followed by mild demand for IT personnel 
in social media, Web development, e- 
commerce, and Bl. 

by Andrew Leibman 
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CASE STUDY 



Peerless Email 
Security 

Axway's MailGate Helps Hay House Publishers 
Manage Its Email With Ease 



by Robyn Weisman 

• • ■ 

Carlsbad, Calif., -based Hay House 
Publishers has specialized in self-help 
books on a wide variety of topics for 
almost a quarter-century. Its authors 
include such well-known authors as 
Deepak Chopra, Suze Orman, and the 
Dalai Lama. Not only does Hay House sell 
books, it also sells DVDs, iPhone apps, 
and a host of related content. It even runs 
an Internet radio station and offers live 
and online events as well as cruises that 
feature its authors. 

Mike Fishell, director of information 
technology at Hay House Publishing, 
says that his company has about 140 
employees worldwide but only two peo- 
ple, including himself, on its IT staff. Al- 
though Fishell admits he wouldn't mind a 




axway 

business, in motion. 



couple more people on his staff, he says 
that one appliance has limited his compa- 
ny's problems with spam and has evolved 
along with the company: Axway's Mail- 
Gate 3650 Appliance (www.axway.com). 

"We get over 10,000 emails a day, of 
which 75% are spam," says Fishell. "For 
the directors' [annual] meeting, I like to 
throw together a little graph to show what 
the cost savings for [MailGate] is alone. It 
pays for itself twice a year." 

The Demo That Never Went Back 

Long ago (at least in IT terms). Hay 
House used a client-based software prod- 
uct on the PCs used by Fishell, Hay 
House CEO Louise Hay, and the editorial 
director. However, Fishell wanted to find 
a solution that worked on the company 
network as a whole. 

MailGate was the second or third prod- 
uct Fishell checked out. He liked the fact 
that MailGate had multiple filtering 
methods that went beyond just Bayesian 
spam filtering to stop spam from clog- 
ging up company mailboxes. Fishell 
looked at a couple of other products, but 
Tumbleweed — the email security com- 
pany Axway later acquired — offered to 
send Fishell a MailGate demo unit. 

"That kind of helped to sell [MailGate] 
to us right there," says Fishell. "Once we 
had it out here for a while, the idea of 
removing it was out of the question." 

Fishell says that price also helped Hay 
House decide on going with MailGate. "It 



[from] the outside to Exchange Server so 
that the server will only accept email 
that's been filtered by MailGate. People 
can't get around it really." 

Fishell says he got used to using a prod- 
uct that was so easy to operate. "For the 
most part, I do updates on it as they come 
out, and that's pretty much the only main- 
tenance I do. Because their updates are so 
frequent, I don't have any problems," 
Fishell says. 

Rather than doing any specific testing. 
Hay House actually put MailGate into pro- 
duction from the moment it received the 
demo unit. "From the time I unpacked the 
box and racked the unit to the time it was 
online was within an hour or hour and a 
half," says Fishell. "Tech support walked 
me through the configuration, which was 
almost nothing. You set up the IP address- 
es, the domains. As for the user accounts, 
the email flows through validly, [and] it 
configures itself." 



doesn't matter how good the product is — 
if it doesn't earn its cost, it's not worth 
purchasing," he says. Moreover, Fishell 
says that he has several users on the Hay 
House network that he describes kindly as 
the sort who are tough to get to move for- 
ward in technology and learn something 
new. "This is important for us because if 
the users are not going to use it, it doesn't 
matter how good [or inexpensive] it is," 
he says. 

Earning Its Keep & Then Some 

Fishell says that Hay House employs a 
Microsoft Exchange Server environment, 
which it has had since the company 
brought in MailGate to handle its spam 
needs. "I have [MailGate] set up to where 
all email flows in from the outside to the 
product," he says. "It works as a gateway 



Like A Third IT Employee 

The money Hay House spends on 
Axway support is well worth it, says 
Fishell. "It's quite competitive," he says. 
"That's a nice thing because with some 
companies, it's like what they charge for 
the support is almost like being robbed for 
what you're getting." 

Fishell says Axway's technical support 
team has been wonderful. "I've used 
them when I had a problem with the 
installation of one of the units," he says. 
"It turned out I got a bad unit, and they 
shipped me a brand-new one that I got 
the next day." 

Fishell also ran into an issue when he 
last upgraded his MailGate hardware. 
According to him, in order to migrate to 
the new unit, he needed to back up the old 
one and import the settings. However, the 
versions of the software on each model 
were different, and he was unable to get 
his older unit up to the same version as 
the replacement one. 

"Support had me do the backup and 
send it to them. They went ahead and 
upgraded it and sent me the upgraded con- 
figuration," says Fishell. "I think I sent it 
around 4 p.m., and by 7:30 [or] 8 o'clock, 
I had the new configuration file and could 
proceed with the upgrade that night." 

Axway's tech support has even helped 
Fishell with building e-commerce poli- 
cies. "Every time we get an order off the 
Web site, the customer gets an email, 
and we get a copy. That way, when [cus- 
tomers] call in, we can pull up their 
orders, which we also use for running 
reports," Fishell says. "[Axway] tech 
support helped me write these policies, 
and I think I spent a total of eight to 10 
minutes on the phone with them getting 
reports automatically emailed to the 
supervisors." 

More Useful With Age 

In Fishell' s estimation, MailGate is a 
much better solution than he had ever 
expected. "Its initial use was for spam, and 
it did exactly what we wanted it to do at 
the time," says Fishell. "We've been using 
[it for] close to seven years, and in that 
time, we've added the policy rule base 
part of it that allows us to get more granu- 
lar on what's accepted, [including] the 
ability to block spoofing of emails. 
They're constantly updating depending on 
whatever issue pops up." 

MailGate also doubles as an email 
archiving solution, which Fishell can set to 
archive emails for a specific length of 
time. "It's a great feature because if some- 
body comes to me with a problem of 
'Person A sent me emails and I'm not 
receiving them,' I have a single point of 
entry for troubleshooting," he says. "I can 
track an email through the email server 
and see if [the user] has the junk filter 
turned on in Outlook or [he or she] ac- 
cidentally deleted it. Tracking email 
through Microsoft Exchange can be quite 
tedious, so MailGate is a valuable tool 
here also." 



Axway MailGate 3650 Email Security Appliance 



An enterprise-class email security appliance that provides comprehensive and highly available 
email security protection at a price targeted to the typical SME. 

"Once we had [MailGate] out here for a while, the idea of removing it was out of the question. . . . 
For the most part, I do updates on it as they come out, and that's pretty much the only mainte- 
nance I do," says Mike Fishell, director of information technology at Hay House Publishing. 

(877) 564-7700 
www.axway.com 
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Datacap FastDoc Capture 



NEW PRODUCT 




by Kris Glaser Brambila 



Data Center | Power | Cooling | Storage | Wireless | IT | Networking | Racks | Servers | Security | Flooring 



Do More With Data 

Datacap's FastDoc Capture simplifies 
the way small and medium-sized organi- 
zations employ and archive document 
data. With FastDoc Capture's document 
automation, users can scan documents 
with any scanner or multifunction periph- 
eral and transfer the data to Microsoft 
SharePoint or other ECM (enterprise 
content management) systems. 

"Datacap created FastDoc Capture to 
meet a growing demand for a document 
capture solution that is simple to set up 
and use," says David Jenness, market- 
ing manager, Datacap. Jenness says 
that, unlike other recognition-assisted 
capture solutions, FastDoc Capture 
eliminates the use of premade templates 
in order to avoid complication during 
use. Instead, FastDoc Capture uses 
automated document identification and 
data location, where FastDoc Capture 
will remember previously scanned doc- 
ument types, such as a medical record. 
"And it will remember where to locate 
the data on the document to populate the 
index fields," Jenness says. 

In addition to other ECM systems, 
FastDoc Capture features a preconfig- 
ured release to Microsoft SharePoint, a 
plus for the many small and midsized 
organizations looking toward SharePoint 
for document management. "Of course. 



Datacap 



you can get data and images integrated 
into any repository with FastDoc, but the 
streamlined hand-off to SharePoint is a 
very useful feature," says Jenness. 

According to Jenness, FastDoc 
Capture's easy-to-use features give it an 
edge over other products that don't offer 




Datacap FastDoc Capture 

Offers easy-to-use capture automation that can be used 
with any scanner or multifunction peripherai to deiiver data 
to IVIicrosoft SharePoint or other ECM systems. 
Price: $2,995 

OCR (optical character recognition), 
automated document ID, preconfigured 
integration to SharePoint, or an afford- 
able price tag. "The ease of use is impor- 
tant, because SMB-type organizations 
may not have deep IT resources. A busi- 
ness manager can set up and use 
FastDoc Capture," says Jenness. 



(914) 366-0100 
www.datacap.com 
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770-931-7732 
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AlphaServer GS160 Model 16 

Base System for OpenVMS 

• DY-160CG-AA 

• One Alpha 21264 Processor 1224 MHz 

• Four Quad Building Blocks 

• One 14-SlotPCI Shelf 

• OpenVMS Operating System License 

ALSO AVAILABLE: 

• Additional 1224 MHz CPU w/SMP 

• Additional Memory 

• Additional PCI Shelves 

• Additional PCI Options 



2 Systems In Stock! 



Authorized COMPAQ' Reseller 

WE WILL BUY YOUR USED HARDWARE! 




We Buy Used 

Cell Phones 



&pay 

upto J 



for each 
phone! 



Some phones have no value. See current purchase price list 
for individual model prices at www.pacebutler.com 



We'll send your check 
within 4 days! 




g Butleni. 



www.pacebutler.com 
1-800-248-5360(405) 755-3131 



Information 
Technology 
Trading 



Experience to find you the 
right technology solution. 

AS/400 • RS/6000 • Sun Microsystems 
Storage • Tape Backup 



(877)715-3686 | www.itechtrading.com 



Insight Systems Exchange 1 

CA$H FOR COMPUTERS 

• Desktops * Laptops 

• Servers •LCDs 
•Printers •Storage 

• Network Gear 

We are ready to buy today! 

Contact: 
Joe Prochelo 
Phone: (714) 939-2376 
Email: jprochelo@in5ightinvestments.com 



Green Actions, 
ereen Results. 



n Insight 

mfm Systems Exchange 

.4 Ovrstn ^Bg"* Mestna^ 



www.desktopremoval.com 



^ MAGNEOT 



Magnext Ltd 

7099 Huntley Rd, Suite 104 1 
Columbus, OH 43229 DATA BACKUP SOLUTIONS 



New & REFURBISHED TAPE & HARD-DISK BASED BACKUP SOLUTIONS 

Library upgrade packages for higher performance & capacity 
Tape library repair specialists - stock lOOO's of parts 

Purchase a complete library with one tape drive 
Get the second tape drive for $1.00 (same format) 

CHOOSE FROM THE FOLLOWING LIBRARY CHASSIS 

• HP SureStore 2/20, 20-Slot Tape Library — $1,999 

• HP SureStore 4/40, 40-Slot Tape Library — $2,449 

• HP MSL6030, 30-Slot Tape Library $2,799 

• HP MSL6060, 60-Slot Tape Library $4,699 

SELECT TAPE DRIVE FORMAT 

LT03 LVD SCSI — $3,500 | LT04 LVD SCSI — $4,500 

m§) mmm mm msm for $1.00 

Condition : Library chassis is refurbislied. Tape drives are NEW \ Warranty: 12-months 
Committed to providing high-value, high-quolity, products to the IT marketplace 



Toll-free 888-NOW-TAPE 
www.magnext.com 



614-433-0011 
info(5)magnext.com 



Pegasus Buys, Sells and Offers Depot 
Maintenance on Kronos Timeclocks 



Specialize in 420G, 
440B, 460F, 480F, 
551, and 4500's 



l_^^K 1 Ethernet Daughter Board, 

, . . ^, . m; I Modem Option, Remote 

: ; : ■"'^NN Readers, Bell Relays, Master 
------ 1 "'^ , Sync, Battery Backup Kit, Dual 

Reader, /O board. External 
Reader I/O Board 

We can supply any configuration you need, if you 
iiave clocl(s installed and need a specific KOS 
version we can help you. Same is true on I/O Boards. 



Pegasus Computer Marketing, Inc. 

(800) 856-2111 I www.pegasuscomputer.net 
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PRODUCT SPOTLIGHT 



Business-Class Notebooks & Netbooks 



Product 



Dell Latitude E6500 



Description 




The Latitude E6500 offers durable magnesium-alloy con- 
struction, a 15.4-inch display (up to 1 ,920 x 1 ,200), and the 
ability for one IT tech to remotely manage the system from 
anywhere via such tools as Dell ImageDirect and Client 
Manager. In addition to a precision-tuned keyboard with 
optional backlighting, the E6500 offers up to 19 hours of 
battery life through the combination of a 9-cell battery, new 
high-capacity battery slice, and ControlPoint software. 

• Drive options include 250GB Free Fall Sensor hard 
drive or 128GB SSD 

• 2.53GHz Intel Core 2 Duo P8700 CPU 

• Built-in eSATA port 

• ControlVault secure credential management software, 
multifactor authentication security, and Dell Mobile 
Data Protection Services 

• Optional biometric fingerprint reader 

Best For: SMEs seeking to cut total cost of ownership 
expenses. 

Price: Starts at $779 



Dell Latitude Z 




Billed as the world's thinnest and lightest 16-inch lap- 
top, the Latitude Z comes with wireless docking and 
inductive charging abilities, Dell says. Measuring just 
over a half-inch thick, the notebook features a 16-inch 
WLED display (1,600 x 900), backlit keyboard, 2MP Web 
cam, EdgeTouch LCD sensor, and fingerprint reader. 

• Dell FaceAware Lock-Out security 

• Dell Capture technology scans and saves business 
cards to Outlook 

• Latitude ON technology supports quick access to 
email, contacts, calendars, and the Web 

• Up to two 256GB SSDs supported 

• 1 .4GHz Intel Core 2 Duo SU9400 or 1 .6GHz Intel 
Core 2 Duo SU9600 

Best For: SME execs who want power with a design 
that makes an impression. 

Price: Starts at $1 ,799; $2,109 with wireless charging 
stand 



DellVostro V13 




Sporting a full-sized keyboard and 13.3-inch LED- 
backlit display (1 ,366 x 768) enclosed in a smudge-free 
aluminum casing measuring just 0.65-inch thick and 
weighing 3.5 pounds, this ultra-light notebook's base 
configuration includes a built-in 1 .3MP Web cam and 
digital microphone, 500GB SATA drive, media card and 
ExpressCard slots, and low-voltage Intel processors. 

• 6-cell Li-Ion battery 

• One eSATA and two USB ports 

• Optional Dell DataSafe online backup and recovery 
service 

• Optional full-disk encrypted hard drive available 

Best For: SMEs and frequent travelers seeking mobility, 
security, and performance. 

Price: Starts at $449 (with Ubuntu OS) 



Contact 



(877) 220-3355 
www.dell.com 



(877) 220-3355 
www.dell.com 



(877) 220-3355 
www.dell.com 



Product 



HP ProBook 5310m 



Description 




At 0.9-inch thin and 3.79 pounds, HP's ProBook 5310m 
is a full-performance system that features a 13.3-inch 
LED-backlit HD display (1 ,366 x 768) that's surrounded 
by an aluminum enclosure. The notebook also includes a 
magnesium-alloy bottom case and ships with a built-in 
2MP Web cam; 4GB of RAM; and HP's QuickLook 3 and 
QuickWeb technologies, which grant access to email, 
contacts, and the Web within seconds of booting up. 

• Windows 7 or Windows XP Pro OS 

• Up to 320GB storage 

• 0.9 X 12.9x8.7 inches (HxWxD) 

• Intel Core Duo SP9300 processor 

Best For: Mobile professionals who value performance 
and affordability in a thin, sophisticated design. 

Price: Starts at $699 



Lenovo ThinkPad Edge Series 




Lenovo's new ThinkPad Edge series includes 13-, 14-, 
and 15-inch models. The 13-inch model is the first 
Lenovo notebook to offer AMD dual-core processor tech- 
nology and the first available with AMD's Vision Pro 
technology; the 14- and 15-inch models will ship in the 
second quarter. In addition to a newly designed, spill- 
resistant keyboard and expanded touchpad, the models 
include Active Protection System and Rescue and 
Recovery technologies. 

• Dual-core AMD Turion and Athlon Neo and Intel Core 

2 processors available 

• Windows 7 optimization via Lenovo Enhanced 
Experience program 

• Wi-Fi, Bluetooth, 3G, and WiMAX connectivity 

• 1 3.3-inch LED-backlit widescreen display (1 ,366 x 758) 

Best For: 24/7, high-performance business users. 
Price: 13-inch model starts at $579 



Lenovo ThinkPad X100e 




Lenovo's new 1 1 .6-inch ThinkPad XI OOe is the compa- 
ny's first ultraportable, professional-grade model to start 
below $500. Featuring support for AMD dual-core Turion 
and Athlon Neo processors and the use of AMD's Vision 
Pro technology, the XI OOe supports Windows 7 Profes- 
sional and comes with various hardware- and software- 
based ThinkVantage technologies to help enterprises 
deploy, manage, and maintain the systems. 

• Dual-monitor support 

• ThinkPlus Priority Support grants 24/7 support to IT 

• 1 ,366 x 768 LED-backlit display 

• Weighs less than 3 pounds 

Best For: Mobile business users with pro-grade require- 
ments. 

Price: Starts at $449 



Contact 



(800) 888-9909 
www.hp.com 



(866) 968-4465 
www.lenovo.com 



(866) 968-4465 
www.lenovo.com 
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Processor's Product Spotlight highlights options available in key data center product categories, providing product information side-by-side for easy comparison. 

Compiled by Blaine Flamig 



Eurocom D900F Panther 
Mobile Workstation Edition 



Eurocom L390T UNO 




The 17.1 -inch D900F Panther is ideal for 
developers, engineers, and other profession- 
als who demand maximum performance, stor- 
age, and video capabilities for software and 
database development; graphic design; 3D 
modeling chores; CAD, CAM, and CAE tasks; 
and mobile server functionality. The system 
supports numerous Windows OSes as well as 
Red Hat and Solaris. Eurocom also sells a 
D900F Panther Mobile Server Edition. 

• Intel Core 17, 17 Extreme, and Xeon 5 
Series CPUs available 

• Up to 2.56TB storage; SLC SDD storage 
available 

• Up to 12GB RAM 

• 1 GB Nvidia GTX 280M graphics (Quadro 
FX3700 graphics soon available) 

Best For: SMEs that need power and mobility 
features in an upgradeable form factor. 



Price: Starts at $2,806 

(877) 387-6266 
www.eurocom.com 




The L390T UNO can help companies make 
significant IT cost reductions via the system's 
space-saving all-in-one design that allows for 
faster installations, relocations, and opera- 
tions over traditional desktop PCs. The L390T 
also features low energy consumption, a long- 
er life span, upgradeability, and the use of 
nontoxic and recyclable materials. 

• 1 9-inch widescreen LCD (1 ,440 x 1 ,050) 
with hard surface or 19-inch widescreen 
five-wire resistive touchscreen display 

• Intel Core 2 Duo, Core 2 Extreme, and 
quad-core processor options 

• Up to 1TB of storage via SATA-300 hard 
drives 

Best For: SMEs in need of low-cost, space- 
saving client systems. 

Price: Starts at $1 ,227 



HP Mini 5102 



HPEIiteBook8450w 




(877) 387-6266 
www.eurocom.com 



The Mini 5102 is HP's first touch-enabled 
netbook model. At 0.91 -inch thin and 
weighing 2.6 pounds, it will easily fit into 
briefcases and bags, while an optional han- 
dle makes transportation even easier. Avail- 
able in red, blue, and black, the Mini 5102 
sports a lightweight, all-metal case and spill- 
resistant OWERTY keyboard that's 95% the 
size of full-sized keyboards. 

• Intel Atom processor 

• Integrated face-recognition technology for 
easy, secure access to Windows and Web 
sites 

• Bundles with Corel Home Office suite 
installed 

• 10.1 -inch LED display 

Best For: Mobile professionals in need of a 
companion PC to perform basic, on-the-go 
tasks. 



Price: Starts at $399 

(800) 888-9909 
www.hp.com 




With a gunmetal anodized-aluminum finish, 
spill-resistant drains, and full magnesium-alloy 
chassis, the 15-inch EliteBook 8450w is 
durable enough to meet military standards 
(MIL-STD 81 OG included) but possesses the 
mobile workstation prowess to support USB 
3.0 performance, four DIMM slots, and future 
Intel Core and i7 processors. 

• HP SkyRoom HD videoconferencing 
software 

• HP QuickWeb, HP QuickLook 3, and 
Power Assistant software included 

• BFR/PVC-free design underscores HP's 
commitment to the environment 

Best For: Power users, developers, and 
designers. 

Price: Starts at $1,499 



(800) 888-9909 
www.hp.com 



Samsung Go N310 




Available in orange, midnight blue, mint blue, 
and jet black, the compact (1.1 x 1 0.31 x 7.26 
[HxWxD]), lightweight (2.8 pounds) N310 fea- 
tures rounded corners and a pebble-stone key- 
board design that allows for larger-than-average 
key spacing. The 10.1 -inch LED-backlit display 
(1 ,024 X 600) is scratch-resistant and uses 
edge-to-edge glass construction, while the 6- 
cell battery provides nine hours of battery life. 

• 160GB hard drive 

• 3-in-1 memory card reader 

• 1 .3MP integrated Web cam 

• Intel Atom N270 processor 

• Easy Display Manager, Network Manager, 
SpeedUp Manager, and other software 
included 

Best For: SME employees who are constant- 
ly on the go. 

Price: $479.99 



Samsung N140 




(866) 726-7864 
www.samsung.com 



The N140 replaces Samsung's NC10 model 
with a more powerful Intel Atom N280 CPU, 
Windows 7 Starter Edition, 250GB hard drive, 
and updated design. Included FailSafe service 
lets users track the system and remotely re- 
trieve, encrypt, and erase data. Other features 
include a 10.1 -inch antiglare widescreen dis- 
play (1 ,024 X 600), 6-cell battery that provides 
10 hours of battery life, gesture-based user 
interface, and Speed Mode button that increas- 
es resources to a user-selected window. 

• 2.8 pounds 

• Accelerated boot-up and access to storage 

• 1 .3MP integrated Web cam 

• Easy Resolution Manager adjusts the 
screen resolution 

Best For: SMEs seeking an easy-to-use sys- 
tem with high-capacity storage. 

Price: $399.99 

(866) 726-7864 
www.samsung.com 



Samsung N510 




With Nvidia Ion LE graphics onboard, the 
Samsung N510 supports HD-capable applica- 
tions that will execute at 10 times the perfor- 
mance of comparable systems. The 1 1 .6-inch, 
1 6:9 display (1 ,366 x 768) includes an anti- 
glare screen, and the keyboard is 97% the 
size of standard keyboards. Gesture-based 
touchpad navigation, a 6-cell battery offering 
seven hours of life, and a 1.3MP motion-acti- 
vated Web cam are also included in a com- 
pact, lightweight frame. 

• 160GB storage 

• Intel Atom N280 processor 

• Windows XP Home SP3 

• 802.1 Ib/g/n 

Best For: Employees needing superior 
graphics performance. 

Price: $599.99 



(866) 726-7864 
www.samsung.com 



Toshiba Portege R600 




The Portege R600, Toshiba's "ultimate ultra- 
light" notebook, weighs only 2.4 pounds and 
measures just 0.77-inch thin but still manages 
to integrate an optional 7mm DVD SuperMuIti 
drive into a magnesium-alloy frame. The note- 
book is also the company's greenest model, 
boasting EPEAT Gold status, EnergyStar com- 
pliance, and RoHS compatibility. 

• 512GB SSD storage 

• 3GB RAM 

• Intel Core 2 Duo SU9400 CPU 

• 7.5-hour battery life from 6-cell Li-Ion bat- 
tery pack 

• 12.1 -inch transreflective indoor/outdoor 
widescreen display (1,200 x 800) 

• Integrated fingerprint reader 

Best For: SME professionals seeking porta- 
bility and style with dependable performance. 

Price: Starts at $2,099 

(800) 597-4512 
laptops.toshiba.com 
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Broadband 
Penetration In The 
United States 

The results of a recent study by the OECD 
(Organization for Economic Cooperation and 
Development) show that the United States 
currently ranks 1 5th in the world for broad- 
band penetration. 

Taylor Reynolds, OECD telecommunication 
economist, is quick to point out, however, that 
mere availability of broadband coverage is 
not the issue. He states, "A lot of people have 
said, 'Well, the U.S. is a big country, and it's 
hard for us to wire such a big country and 
give everyone broadband, and that's the rea- 
son we're fifteenth place,' but the reality is, 
almost everyone in the U.S. who wants 
broadband can get it." According to the 
OECD's data, the United States enjoys 82% 
coverage from DSL services and 96% cover- 
age from cable. 

Therefore, the more prescient questions are 
not about coverage per se, but about prices, 
service, and the quality of the network infra- 
structure. For example, France (and many 
other countries) has broadband speeds of 
26Mbps, whereas in the United States, aver- 
age advertised broadband speeds are around 
7 to 8Mbps. Further, French telecommuni- 
cations subscribers can purchase a broad- 
band, cable television, and telephone service 




bundle for around $45 per month, whereas a 
similar package in the United States is avail- 
able for no less than $100. 

A lack of competition in U.S. broadband mar- 
kets appears to be contributing to the dearth 
of competitive pricing. According to Reynolds, 
"You have less competition [in the U.S.] than 
most other countries, because your broad- 
band choices are limited to one cable pro- 
vider and one DSL provider, in large part." 

The primary issue that broadband faces in 
the United States, though, is the need for bet- 
ter network infrastructure. "A lot of countries 
are still focusing on DSL technologies, and 
DSL's great, and it's pretty much the founda- 
tion of broadband in most OECD countries, 
but the upload speeds are very slow. That's 
where it's really important to upgrade to fiber 
optic networks," says Reynolds. 

Fiber cables offer symmetric bandwidth to 
handle uploads and downloads simultan- 
eously, at much faster speeds than anything 
DSL or cable can provide. This is affecting 
enterprises that are unable to acquire the net- 
work bandwidth they need in consumer-grade 
broadband. They have to pay for an expen- 
sive lease line to get the service they need. 

"Pretty much the whole industry is moving 
toward fiber because it has near-limitless 
capacity," continues Reynolds. 'These under- 
sea cables that connect countries typically 
have four fiber cables in them. A very small 
number of cables can handle massive amounts 
of capacity. The networks need to be better, 
and they need to do this upgrade to fiber." 

by Seth Colaner 



Making The 
CIO/IT Manager 
Position A Strategic 
Business Role 

New Expectations Will Have Managers 
Partnering With Execs On Business Initiatives 



by Kurt Marko 

A RECURRING, frustrating problem for IT 
personnel is demonstrating to management 
that investing in IT provides significant 
business value and isn't just money wast- 
ed. In today's economy, an IT manager 
can't merely be an efficient, cost-effective, 
and reliable operator of technology infra- 
structure and information systems. Now, 
business executives expect IT managers 
to operate further up on the value chain as 
strategic partners in new business initia- 
tives. Execs need them to transition from 
being internally focused technology pro- 
viders to business-savvy participants in 
corporate strategies to generate new cus- 
tomers, develop or improve products and 
services, and, ultimately, increase prof- 
itability throughout the enterprise. 

According to Richard Hunter and George 
Westerman, "Managers throughout the busi- 
ness want value from IT, and they're pretty 
sure [you, the CIO, aren't] delivering it." 
The men co-authored "The Real Business of 
IT," in which they give recommendations 
for transforming IT departments and the 
CIO's role. 

Reasons Behind The Shift 

Hunter and Westerman explain that there 
are two overarching trends fueling IT's 
strategic imperative. First, they write that 

CIO/IT IVIanager 
Recommendations 

• Forge links between business and IT 
strategies and processes. ClOs must 
maintain an end-to-end view of tech- 
nology's role in delivering business value. 

• Develop indicators that link IT perfor- 
mance metrics to business goals. Shift 
IT'S mentality from operations to rev- 
enue generation. 

• Cost-cutting won't cut it. Turning off tech- 
nology investments during a downturn is 
counterproductive. 

• Leverage the IT team. Ensure IT staff 
communicates regularly and effectively 
with business partners. 

Source: "The CIO Is Not Dead"; Info-Tech Research Report 

BY BUSHRA TOBAH; JULY 21 , 2009. 



as technology has permeated everyday life, 
IT has become inextricably entwined in 
business processes. Second, they see a gen- 
erational shift in the CEO position: 40- 
something, midlevel managers have spent 
their entire careers in the era of PCs and 
thus understand how to apply technology 
to business problems are replacing older 
executives who were reared and seasoned 
in a less technologically pervasive era. 



Jack Santos, executive strategist for 
Burton Group, says his firm has identified 
three processes reshaping enterprise IT: 
externalization, consumerization, and 
democratization. These overarching trends 
are leading IT managers to offload non- 
core activities; react to the pervasiveness 
of consumer devices and services; and 
adapt to more direct, social network- 
fueled communication channels. Each is 
forcing IT into a more strategic role, 
according to Santos, and in combination 
are leading to what he terms "a postmod- 
ern IT," which focuses more on setting 
strategic directions for technology, archi- 
tecture, or vendor management rather than 
infrastructure operations. 

Despite these compelling develop- 
ments, Info-Tech Research Group analyst 
Bushra Tobah says she doesn't see a sud- 
den revolution in the CIO's role; rather, 
she anticipates a general shift where busi- 
ness managers have elevated expectations 
of IT, expecting the department to dem- 
onstrate value by providing consistent 
and reliable services with greater finan- 
cial transparency. 

l\/lal(e The Transition 

Hunter's and Westerman' s book pre- 
sents a detailed, lengthy, and case study- 
filled program for CIOs seeking to 
improve their department's strategic busi- 
ness value — one that is summarized by 
four key steps. The first involves a mind- 
set shift from thinking of IT as a technolo- 
gy provider to a business services supplier. 
Thus, IT doesn't run servers and routers 
but delivers applications and communica- 
tions. Second, IT must improve and com- 
municate its value as a service provider. 
As Hunter and Westerman put it, "you and 
your team [must] demonstrate that the IT 
organization is providing the right ser- 
vices, at the right level of quality, at a 
competitive price." 

As IT establishes its ability to consis- 
tently and competitively deliver services 
on time and on budget, Tobah says the 
next step up the value pyramid is identify- 
ing technologies that contribute to busi- 
ness success. Hunter and Westerman 
translate this into making the connection 
between IT investments and improved 
business performance, the third of their 
transformational steps. They see IT creat- 
ing business value in two ways: improving 
decision-making through better and more 
timely information or increasing the effi- 
ciency, quality, and functionality of busi- 
ness processes. 

A primary way IT managers can under- 
stand their business strategy, according to 
Tobah, "is to be a real student of your com- 
pany." Tobah and Santos both say an effec- 
tive means of communicating the value of 
IT and linking it with overall business 



needs is to establish an IT steering or advi- 
sory committee. 

It's also important to engage IT staff in 
the process of strategic transformation. 
Hunter says an effective way of changing 
intransigent mindsets is challenging peo- 
ple to eliminate technology buzzwords 
from their vocabulary and replace them 
with business-oriented terms. Likewise, 
he says IT staffers should be required to 
connect their activities with actual busi- 
ness outcomes. 

Santos adds that including staffers in rele- 
vant steering committee discussions can 
also increase engagement. In general, Tobah 
says IT managers should encourage every- 
one to proactively, if not aggressively, seek 
out colleagues in other business units to 
understand their IT needs and forge better 
working relationships. Santos notes that 
because the postmodern IT is increasingly 
reliant on outside suppliers for noncore 
technology services, staffers must become 
cross-functional and more versatile. 

Once the CIO and IT department writ 
large reach a level of strategic significance. 



Key Points 



• IT department personnel must focus on 
delivering services that provide tangible 
value to the underlying business and not 
operating technology infrastructure. 

• IT managers can improve business inte- 
gration by fostering communications with 
their business unit peers, establishing 
steering or advisory committees, and 
encouraging staffers to proactively solic- 
it IT requirements from their business 
unit colleagues. 

• IT personnel must change their mindset 
from being providers of technology to a 
department that supplies business ser- 
vices. The IT department's goal must be 
to improve business performance as mea- 
sured by business or financial metrics. 



with established credibility across other 
business units and their managers, the last 
stage of Hunter's and Westerman' s trans- 
formation process is the augmentation of 
it's responsibilities across other business 
functions such as HR, corporate procure- 
ment office, or customer support. 

Recommendations 

The path to a strategic IT department 
can't be traversed overnight. Hunter says 
a full transition often takes five or six 
years. Yet, incremental improvements are 
possible. Westerman says he's seen IT 
departments "go from a total train wreck 
to become business partners in one or two 
years." He adds that in the early stages, an 
IT department can quickly establish value 
for the money and dramatically change 
the tenor of its relationship with other 
busi-ness units. Experts agree that a strate- 
gic strengthening of an IT department's 
(and by extension, the CIO's) role isn't 
unique to large corporations but is benefi- 
cial for SMEs, as well. Santos notes that 
regardless of size, companies aren't going 
to forget the lessons of the recent reces- 
sion — even when economic conditions 
turn, they'll be tightly monitoring and 
managing their IT spending. So, although 
Burton's postmodern IT department may 
be smaller, its focus will be on activities 
with greater business value, spanning 
internal business units and external suppli- 
ers. Despite the challenges. Hunter and 
Westerman are enthusiastic in their con- 
tention that "there has never been a better 
time for a capable executive to take on the 
role of CIO." 
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Invasion Of Portable Devices 



Tips & Advice For IVIobile Device IVIanagement In The Enterprise 



by Kurt Marko 

Mobile devices, namely smartphones, 
which bear as much resemblance to tele- 
phones as laptop PCs do to typewriters, have 
invaded the office, campus, warehouse, 
cafe — just about everywhere people work. 
As anyone who follows the market with even 
cursory interest can attest, the technology 
and feature set of mobile devices is evolving 
at a breakneck pace. 

In the paleo-smartphone (read: pre- 
iPhone) era, enterprise users were largely 
limited to BlackBerrys, but the iPhone was a 
game changer, according to Paul DeBeasi, 
Burton Group's senior wireless and mobility 
analyst. Led by executives who couldn't 
resist Apple's revolutionary gadget, DeBeasi 
says the iPhone created a wave of smart- 
phone heterogeneity that is unlikely to be 
turned back. "The days of pure IT control 
are gone," DeBeasi says. Bolstering his 
assertion, a recent survey by Forrester 
Research of several hundred mobility tech- 
nologists and decision-makers found more 
than half of enterprises already support two 
or more mobile platforms, with a like num- 
ber supporting personal, employee-owned 
hardware. Given such device diversity, IT 
support issues quickly get complex. 

Company-Owned Or Personal? 

There are two primary support models for 
mobile devices in the enterprise: Phones are 

Top 20 Mobile Device 
IVIanagement & 
Security Best Practices 

1. Segment your workforce. 

2. Build in flexibility by enabling device 
diversity. 

3. Invest in a mobile device management 
solution or managed service. 

4. Utilize a single Web-based console for all 
management and security operations. 

5. Outline procedures for requesting and 
obtaining mobile devices, applications, 
and services. 

6. Spell out appropriate use. 

7. Plan to support personal devices. 

8. Clearly define who is responsible for 
mobile expenses and to what extent. 

9. Explain internal and external service 
desk support availability. 

10. Avoid the company logo on mobile devices. 

1 1 . Enforce a strong password policy. 

12. Automate remote device wipe after 10 
unsuccessful authentication attempts. 

13. Remotely lock or wipe all lost or 
stolen devices. 

14. Encrypt the data. 

15. Limit the data stored on the device 
through document portal usage. 

16. Provide multichannel training and 
links to additional resources. 

17. Embrace Web 2.0 as a means to 
reinforce best practices training. 

18. Display a telephone number on the locked 
screen to call if a lost device is found. 

19. Enable users to help themselves and 
lower support costs. 

20. Leverage remote control functionality 
to troubleshoot issues faster. 

Source: "Twenty Mobile Devioe Management Best Practices: How 
To Improve Mobile Support For Your Anytime, Anywhere 
Workers"; Forrester Research Report by Benjamin Gray with 
Simon Yates and Christian Kane; October 2009. 



either company-procured and -managed or 
personal and employee-owned but also used 
at work. Historically, phones used strictly for 
business were supplied only to employees in 
specific job categories and tightly controlled 
by IT, which acted as a middleman between 
the end user and carrier. With iPhone-fueled 
smartphone proliferation, more employees 
began using personal devices at work, primar- 
ily for email and scheduling. 

According to DeBeasi, many companies 
are embracing this consumer-driven model — 
typically by granting employees a monthly 
stipend to cover part of their carrier subscrip- 
tions — because it gives employees freedom 
to choose the phone best-suited to their needs 
and tastes while limiting IT's support and 
procurement responsibilities. A recent survey 
by the Aberdeen Group found that 75% of 
enterprises allow use of personal devices at 
work, with almost half claiming this procure- 
ment model reduces costs. 

The choice between a flexible, "bring your 
own" phone policy and a restrictive, compa- 
ny-controlled stance often boils down to a 
firm's risk aversion and mobility goals, notes 
DeBeasi. "First you have to decide what you 
want out of a mobile device," he says. "Is it 
just for email and calendaring, or do you also 
want to run enterprise applications?" 

Even with a permissive phone policy, 
Info-Tech senior research analyst Mark 
Tauschek advises trying to limit the number 
of different mobile operating environments 
by standardizing on a middleware synchro- 
nization interface (so-called push email) 
between the phone and enterprise email sys- 
tem — typically either Microsoft's Active- 
Sync for Exchange or BlackBerry Enter- 
prise Server. 

Sanctioning personal phones doesn't imply 
an "anything goes" policy, adds Tauschek. 
Although employees may be able to select 
and use their own devices, IT needs some 
clearly stated policies. For example: "You 
have to play by our rules; we'll manage the 
device, and we'll own the phone number," 
Tauschek says. Yet, policy enforcement can 
be a sticky problem, which is where mobile 
device management software comes in. 

In a recent report outlining mobile device 
best practices, Forrester senior analyst 
Benjamin Gray recommends investing in a 
mobile management solution, which can be 
either a dedicated, internally operated soft- 
ware platform or a cloud-based managed ser- 
vice. He says these products enable IT to 
enforce strong security policies; track and 
monitor devices; provision new smartphones; 
manage settings and configurations; and even 
enable remote troubleshooting, configuration 
resets, and data wiping. With scores of indi- 
vidual devices roaming around outside the 
office, trying to centrally manage a smart- 
phone fleet without some automation soft- 
ware "is like death by a thousand cuts," says 
Alan Dabbiere, chairman of AirWatch 
(www.air-watch.com), a mobile device man- 
agement provider. 

Core Best Practices 

Whether using automated centralized 
device management or merely relying on 
individual employees to follow written secu- 
rity policies, experts agree on a set of core 
best practices for all smartphones used in the 
enterprise. The most basic measure is setting 
a password or PIN code to unlock the device 
after a certain period of inactivity. While 
older phones might support only a four-digit 



Key Points 



Smartphones have become an essential 
device in the mobile enterprise, yet most 
organizations haven't developed strategies 
for deploying and managing them in an 
era when half or more may be personally 
owned by employees. 
Allowing personal smartphones with a 
monthly service stipend can reduce IT sup- 
port costs while increasing employee pro- 
ductivity and job satisfaction. 

IT needs to develop and communicate 
smartphone security and support policies, 
along with measures for policy enforcement. 



PIN, most now accommodate alphanumeric 
passwords, so IT may also want to set guide- 
lines on password quality and a rotation 
schedule. 

Another necessary security step, according 
to DeBeasi, is the ability to perform a remote 
wipe, erasing all data on the phone and reset- 
ting its configuration, should the phone be 
lost or stolen. 

The next level of security entails encrypt- 
ing data on the device and in transit over 
Wi-Fi LANs. Most current smartphones, 
including Windows Mobile devices, Black- 
Berrys, and iPhones, natively support local 



data encryption. For data in transit, smart- 
phones should support 802. Hi (WPA2) 
WLANs (most do). Finally, the National 
Institute of Standards and Technology rec- 
ommends "Bluetooth devices are turned off 
when they are not needed to minimize expo- 
sure to malicious activities." 

Support Policies 

Regardless of whether smartphones are 
corporate-owned or personal, Tauschek 
believes enterprises need to develop a wire- 
less support plan. He says IT needs to make 
clear which issues employees should take to 
their internal help desk and which to the carri- 
er. With personal phones, he says the first 
point of contact should be the internal help 
desk only for internally provided applications 
and services, while employees with corpo- 
rate-provided phones must contact the help 
desk for everything. He says it's important 
employees get training on support procedures 
and security policies and understand the con- 
sequences for policy violations. 

As smartphones pervade the enterprise 
and the device landscape becomes increas- 
ingly diverse, Dabbiere says support is 
becoming a much bigger issue and is a 
major reason behind the growth in special- 
purpose mobile management software. "Our 
goal is to make the problem of mobility go 
away," he says. In summing up the compet- 
ing issues confronting IT managers. Gray 
writes, "Mobile device management and 
security will forever remain a balancing act 
between the productivity drivers of the busi- 
ness and security and cost requirements for 
IT." However, given the importance of 
mobile devices to today's workforce, these 
are problems IT can ill afford to ignore. 01 
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Surviving Your 
Electronic Health 
Records Project 

Experts Offer Their Advice 

For IVIaking The Implementation Smooth 



by Sue Hildreth 

In 2002, Cedars-Sinai Medical Center in 
Los Angeles launched its new electronic 
physician order entry system. Three 
months later, 400 of the hospital's physi- 
cians demanded the software be removed. 
Later reports cited poor navigation and 
usability and inadequate user training. 

EHR (electronic health records), like any 
major software project, has to be imple- 
mented thoughtfully, with time planned 
into the schedule for user education, test- 
ing, and customization. In a hospital or 
physician clinic, the 24/7 nature of the 
operation can make it tempting to do an 
EHR implementation quickly and hope for 
minimal disruption to the staff. But an 
EHR project that is carefully planned with 
extra time allotted for testing, training, 
integration, and data migration will usually 
go more smoothly than rushed projects. 

"We start with a series of planning dis- 
cussions before any work starts," says 
Barbara Cox, president and CEO of Gap 
Consulting, an EHR consultancy. "We 
create a project charter, goals, objectives, 
[and a] list of the types of change that 
have to be endured, the timeline, re- 
sources, and assumptions." 

Health History 

EHR systems, which include such things 
as electronic patient charts, physician order 
entry, doctor's notes, lab results, and e-pre- 
scribing, make it much easier for doctors 
and other caregivers to see a patient's health 
history and to more quickly get records and 
test results to other providers. They can also 
improve patient safety by red-flagging 
potential treatment errors. EHR will also be 
required software at all hospitals and physi- 
cians offices in the next five years. 

But EHR also involves drastic changes in 
work processes, especially for physicians 
used to writing on paper charts. The systems 



involve the integration of software and data 
in various departments throughout the hos- 
pital, including admitting, the emergency 
room, and radiology, as well as with outside 
labs and clinics, and sometimes with region- 
al health information exchanges. EHR 



Key Points 



• EHR involves drastic clianges in worl< 
processes, especially for physicians 
used to writing on paper charts. 

• User training is critical to adoption of 
EHR systems. 

• Testing should be done throughout 
the implementation. 



systems are complex, costly, and usually 
time-consuming to install. According to 
Hypatia Research's "ARRA and EHR: 
What Healthcare Providers Need to Know 
About the American Recovery and 
Reinvestment Act and Electronic Health 
Records," the cost of EHR software and 
implementation services for even a small 
hospital may reach about $3 million. 

Successful Implementation 

To better ensure a successful EHR 
implementation, experts at EHR software 
companies and consulting firms offer their 
advice for making the implementation 
process smoother. 

Recruit non-IT staff. EHR systems 
touch every area of the hospital, not just 
the IT department. They also usually rep- 
resent major changes in work processes 
for the employees, often more than with 
other enterprise software such as ERP and 
CRM. Non-IT staff should be involved 
throughout the project to help spot poten- 
tial problems with the new workflow or 
screen navigation and to help with com- 
munication and training within their areas. 



Workflow, then and now. Putting in a 
new enterprise application almost always 
entails changes to employees' work pro- 
cesses. Hopefully, the new workflows are 
more efficient than the old ones, but 
regardless, they're different and often 
unwelcome to employees. Have IT and 
non-IT staff identify the various work- 
flows that will be affected and map out 
how they will be changed. This will help 
spotlight problems with the new workflow 
and give employees a better understanding 
of how the new system will work. 

24-hour support. A hospital treats 
patients at all hours, so its EHR system has 
to be available around the clock as well, at 
least for the first two or three weeks of an 
implementation. However, not all software 
vendors expect to provide 24-hour support, 
so discuss it with the EHR vendor early on 
and work out a backup plan if need be, 
advises Cox. She also recommends 
appointing a triage coordinator to assess 
how well problems are being handled dur- 
ing the rollout. A daily change meeting to 
discuss changes to the implementation and 
any problems is also important, says Cox. 

User training. User training often gets 
low priority, but for EHR systems in par- 
ticular, user training is critical to adoption. 
Frustrated users will simply refuse to use 
the software or use it incorrectly, creating 
errors. Offer initial training on the product 
during the last couple of weeks before 
implementation as well as early in the roll- 
out. To make training more convenient 
and ensure people retain what they've 
learned, provide multiple types of training, 
including instructor-led classes, computer- 
based training via the Web or a CD, and 
hands-on practice. "Pre-training, post- 
training, refresher training ... It's impos- 
sible to train too much," says Paul 
O'Toole, senior vice president of opera- 
tions for Healthland (www.healthland 
.com), an EHR software maker. 

O'Toole recommends getting a group of 
super users trained on the system early in 

Government Funds EHR 



the process to ensure there are plenty of 
helpers available to help users navigate the 
system when it goes live. "They're the 
ones that will be hand-in-hand with the 
docs, making sure they're comfortable 
with the EHR," he says. 

Testing. There are multiple moving parts 
in an EHR system that can go wrong. So 
testing should occur throughout the imple- 
mentation as each new function or module 
is rolled out. O'Toole says that the integra- 
tion points between different software sys- 
tems inside and outside the hospital, as well 
as with medical devices, have to be 
checked carefully. "You have to make sure 
the data is flowing properly," he says. 

Data translation is another potential 
problem area that requires careful check- 
ing. After a data conversion, Pam Wostar- 
ek, regional implementation manager for 
EHR software company NextGen 
(www.nextgen.com), says she has clients 
do thorough data point reviews and side- 
by-side comparisons of charts and screens 
to spot discrepancies. 

User acceptance testing is not only a 
good idea, says Cox, but something that 
should be done more than once. She rec- 
ommends three cycles of user acceptance 
testing, with each one followed by a report 
on the issues the users encountered. 

Governance. Any major software system 
requires constant maintenance after it has 
been deployed. But if it's a brand new apph- 
cation such as EHR, there may be no exist- 
ing group that is tasked with administering 
it, causing it to be essentially abandoned 
after the rollout and initial fanfare end. 

"One of the biggest mistakes is leaving 
the product to manage itself, without any 
governance for how to manage the appli- 
cation," says Wostarek. "Governance 
involves assigning committees of individ- 
uals to look at content in upcoming releas- 
es and upgrades [and] look at changes in 
workflow [and] at changes in the organi- 
zation, and ask, 'Do we need to change 
anything [in our EHR system]?'" 



Electronic health records software has the potential to improve both the efficiency and cost-effec- 
tiveness of hospital operations and the safety of patients. IVIoreover, keeping patient information in 
a standard, digital format means it can be quickly shared with other providers, such as when a 
patient travels out of state and requires emergency medical care. Both state and federal govern- 
ments have been promoting EHR adoption by hospitals and doctors and, in early 2009, President 
Barack Obama signed the economic stimulus bill, which included money for EHR. 

The funds include a number of grants to states, along with Medicare and IVIedicaid incentive pay- 
ments for hospitals and physician practices that implement EHR and penalties for those who don't 
after 2015. This year, the government will publish its criteria for what an EHR system needs to 
qualify for the bonus funds. For more information, go to healthit.hhs.gov/portal/server.pt. 



-lo-veati vn^oYf 



■^0^^^'^ .^^ and tips lo help you do your job 

'''^I'.cs r.c>n. cquip.n.nt nu.nutarturcrs and leselletS YOU CHH ^^^^^ 



xy^s^ "^^^^ '"^^'^'I'tiished 



,;.r and si.pler ,o use than tod,,, "'^^^^^ 



peaiers that can sery,,^ 



iii-ticptli 



'"alio. 



%Cll 




tools 



Of 



0, 



'III 



What are 

PROCESSOR & 

PROCESSOR .COM 

all about? 




January 15, 2010 



Processor.com 



Page 43 



News 



Understanding 
The Rules 

Software Licensing In A Virtualized Environment 



by John Brandon 

In the days before virtualization 
became so common in data centers, soft- 
ware licensing was fairly straightforward: 
Software could only be used on one physi- 
cal computer. When you needed to install 
software on another computer, you had to 
buy another license. 

With virtualized servers, software 
licensing became much more complex. 
Software vendors don't always have clear 
rules governing how many times an appli- 
cation can be installed on a server that 
might be used for multiple instances of the 
same server OS (say, one for quality 
assurance and one for production) and, in 
some cases, do not distinguish well 
between the physical computer license and 
the "instances" of an OS. 

Sue Raisty-Egami, an analyst with Sure 
Product Consulting (www.sureproduct 
consulting.com), says the issue is com- 
pounded even further when it comes to 
licensing "per-CPU" (on a server that 
might have multiple CPUs) or when a vir- 
tualized server is deployed as a mirror, say 
to a hosting provider or to a branch office. 
She says many IT managers get confused 
about licensing because there is a tenden- 
cy to think the company has purchased 
multiple licenses of a product, so there 
should be freedom in deciding how those 
licenses are used on which servers and 
also for VM mirroring. 

"Vendors are not exactly excited to let 
purchasers lower costs this way, especially 
if they predominately licensed on a 
per-CPU basis," says Raisty-Egami. "So 
some now license on a combination of 
per-instance and per-CPU, and some have 
built license enforcement code into their 
software that prevents multiple instances 
from running on a single physical machine." 

Raisty-Egami advises companies to read 
software licensing agreements carefully 
and request the opportunity to test soft- 
ware in their virtual environment before 
making final purchases. 

"Purchasers should not assume that the 
software license will just work in multiple 
instances, where each instance runs within 
its own virtual machine," she says. "Some 
software packages have license enforce- 
ment built in that would prevent it from 
running on two virtual machines on the 
same physical server. The software might 
only be installable once on a machine with 
a particular MAC address." 



Key Points 



• Software licensing in a virtual environ- 
ment is still evolving. 

• Some vendors use par-processor and 
per-instance licensing. 

• Compliance is a major issue in case soft- 
ware licenses are audited. 



Compliance Issues 

One of the reasons there is some con- 
sternation over the issue of software 
licensing is that in an audit, a company 
might be exposed for using software ille- 
gally without even knowing it had made 
the mistake. For example, with VMware, a 
company might have several instances of 
an SQL server on one physical box, think- 
ing that — at least for that software — it is 
safe to run multiple instances, when in 
reality, the vendor has strict rules about 
virtualization licensing. 

"You don't really get a benefit from a 
licensing perspective, whether it's virtual- 
ized or a physical box," says Scott Gon- 
desen, a director of client services at RSA 
(www.rsa.com). "The biggest pitfall is that 
some companies don't have a good under- 
standing of the licensing mechanisms, and 
so what they'll do is they'll create a virtual 
server with several guest operating systems 
and think that they can get by with just a 
single processor license. 

"So that can put them at risk from a com- 
pliance standpoint. An auditing type situa- 
tion would certainly uncover that, and there 
can be some financial ramifications for 
them, especially if they knowingly did that." 

Another issue to be aware of is that in 
some cases, you may have the software 
licensing well established in a virtual envi- 
ronment, but because server virtualization 
provides such an easy path for customiza- 
tion and making changes to configurations 
in a data center, you can quickly become 
noncompliant in regard to software licens- 
ing. To prevent this, it's important to keep 
records of exactly how software is used on 
virtual servers and track any changes to 
licensing on those servers. 

Other Approaches 

Of course, because the IT industry has 
learned to be flexible and can approach 
licensing using a variety of solutions, there 
are creative ways to deal with licensing 



Virtual Server Cloning 

Sure Product Consulting (www.sureproductconsulting.com) analyst Sue Raisty-Egami says virtu- 
al server cloning is another issue to be aware of in a virtual server environment, due to how easy 
it is to lose track of which licenses are being used on which sen/ers. 

"One big feature of virtualization software is the ability to clone virtual machines," she says. "If the 
VM you are cloning contains software that is licensed per-instance with a unique serial key, you 
are very likely to violate the license because all of your clones would use the same serial key. 
You might find the software doesn't work at all as a result." 



issues. Preston Lee, CEO of OpenRain 
(www.openrain.com), says the approach it 
uses — even though it deployed Mac com- 
puters for end users — is to use Linux as 
part of the equation. With Linux and open- 
source software on the back-end, he says 
they have avoided the typical pitfalls 
of licensing in a virtual environment. 
Another approach it uses is to offload 
some applications and services to the 
cloud, which admittedly does have its own 
set of licensing challenges, but they are 
usually handled by the cloud provider and 
help companies avoid the typical compli- 
ance issues that arise. 

Wayne Federico, CIO of Miro Consulting 
(www.miroconsulting.com), says the best 
approach to software licensing is to have a 
specific design in place for how to handle 
licensing, one that addresses the specific 
licensing requirements for each virtual 
server vendor. 

"Many companies configure their envi- 
ronments first, then ask questions," says 
Federico. "Strategies differ for each par- 
ticular software vendor more than they do 
the different virtual server technology 
options. Each software manufacturer will 
address their licensing requirements with- 
in server-virtualized environments based 
upon their expectations of use. The diffi- 
culty for software manufacturers today is 

With virtualized 
servers, software 
licensing became 
much more 
complex. 

that server-virtualized technologies and 
solutions are [constantly] changing and 
evolving, and they must constantly adjust 
their own licensing requirements to ad- 
dress technological changes." 

Federico says IT managers must become 
"virtual licensing experts" in the sense that 
they know how the technology itself is 
changing and how the licensing is adapt- 
ing, and they keep tabs on such subtleties 
as per-processor licensing as the industry 
evolves and approaches the issue differ- 
ently. He says this is a particularly chal- 
lenging issue because there are so many 
benefits of a virtualized environment that 
licensing is often overlooked as a problem. 
And, it is often difficult enough to manage 
the licenses themselves, tweak perfor- 
mance, and meet business needs for appli- 
cations. The key, he says, is to have a 
matrix of all software licenses and how 
they are used in the virtual environment. 

In the end, virtualization does bring 
major benefits to IT. Licensing is one of 
the stickier issues for managing the envi- 
ronment, but having a plan in place will 
offset any potential pitfalls. 



I Qualcomm COO 
Announces Departure 

Qualcomm will have a new COO starting 
Jan. 1, as Qualcomm's current COO, Len J. 
Lauer, has announced that he is departing 
the company to take a CEO post at an 
unnamed firm. Qualcomm President Steven 
R. Altman will take over Lauer's duties, with 
the exception of the company's MEMS 
Technologies unit, which will be headed by 
Steven M. Mollenkopf, Qualcomm's current 
executive vice president and president of 
Qualcomm CDMA Technologies. Lauer has 
held a number of other positions in the indus- 
try prior to his time at Qualcomm, including 
sen/ing as COO at Sprint Nextel right before 
coming to Qualcomm; he has also worked 
with IBM and Bell Atlantic. 




I Judge Orders Microsoft 
To Pay Legal Fees 

A judge in Wisconsin's District 1 Court of 
Appeals has ruled that Microsoft does indeed 
need to pay opposing counsel legal fees in 
a long-running case in Wisconsin. Judge 
Richard J. Sankovitz affirmed a lower court's 
ruling that the software giant owes about $5.6 
million to law firm Zelle, Hofmann, Voebel & 
Mason LLP, which represented plaintiff 
Candace Bettendorf and others in a 2003 
antitrust suit over the amount of money 
Microsoft charged indirect purchasers for 
software. The law firm had sought more than 
$24.1 million, which both the trial court and 
the court of appeals found excessive. 
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I 2009 A Big Year For Netbooks 

Shipments of netbooks more than doubled in 
2009, with a 103% increase over the previous 
year, according to the NPD Group's Display- 
Search. About 33.3 million of the low-cost lap- 
tops shipped last year, outpacing the paltry 5% 
growth rate of full-fledged notebooks but still 
falling behind the full-sized laptops' tally of 
136.3 million units sold. Netbooks also posted 
the sole gains in revenue in the portable PC 
category for 2009, logging a 72% climb to 
$11.4 billion. In 2010, shipments of netbooks 
should rise 19%, with notebooks gaining 16%. 

I 3Com Earnings Rise 
In Second Quarter 

The second-quarter financial earnings for 
3Com were higher than expected, with a 55% 
increase in overall profit. Specifically, 3Com 
raked in $20 million, up from $12.9 million a 
year eartier. Despite the impressive hike in 
profit, revenue decreased by 9.1% to $322.2 
million. This is likely the last earnings report 
from 3Com before HP is set to take over 
the networking company in a deal worth $2.7 
billion. 3Com's branches include Tipping 
Point, H3C, and the original 3Com. H3C is 
connected to Huawei, a company whose 
sales dropped 35.5% to 18.2 million. 
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I Gartner: 2009 A Bad Year 
For Semiconductor Industry 

A report released by Gartner indicates that 
worldwide semiconductor revenues were 
down 1 1 .4% to a total of $226 billion in 2009, 
which the research firm says is $29 billion 
lower than in 2008. However, Gartner notes 
that after the first quarter, the semiconductor 
market saw quarter-over-quarter growth 
throughout the rest of 2009. According to 
Gartner's study, companies hit hardest by 
the recession this year include Infineon 
Technologies, which Gartner predicts will see 
a 46.5% drop in sales; Renesas Technology, 
which is predicted to see a 1 9.9% drop in 
sales; and AMD, which Gartner expects to 
take a 10.1% drop. 

I Red Hat Revenue 
Driven By 
Subscriptions 

Open-source 
software vendor 
Red Hat saw an 
increase in revenue 
in the third quarter, su 
passing analyst expecta 
tions. The company revealed its Q3 
earnings were $194.3 million, an increase 
of 18% since last year's third quarter. Red 
Hat's 3Q subscription revenue, which 
accounts for about 85% of the company's 
total revenue, increased 21% year-over- 
year to $164.4 million. Deferred revenue 
grew to $619 million, increasing 23% since 
the same time last year. Net income was 
down to $16.4 million from $24.3 million last 
year, due in large part to some litigation 
costs that lowered the company's stock 
value. The company predicts fourth-quarter 
revenues of about $191 million to $193 mil- 
lion this year and nearly a quarter of a bil- 
lion dollars (between $743 million and $745 
million) for full-year revenues in 2010. 

I Judge Dismisses Apple Suit 

Apple will not see further litigation in a class- 
action suit brought against it alleging that the 
company knowingly shipped ilVlacs with de- 
fective screens. A judge in California has dis- 
missed the case, citing the allegations as too 
broad to be tried. The problems arose in 
ilVlacs shipped in 2006, and recent ilVlacs are 
rumored to have similar issues. Apple may 
not be completely in the clear, however, as 
lawyers for the plaintiffs may yet be able to 
bring the case if they successfully address 
the scope issues that caused the judge to 
dismiss the case. 



SIX QUICK TIPS 




I Comcast Pays Up 



Rather than face further legal action, Comcast 
will pay out $16 million in rebates to 1 million 
Comcast customers who were affected by the 
company's actions to obstruct peer-to-peer 
traffic. Comcast said its practices to control 
Web traffic were done to free up bandwidth, 
but it has not admitted to any wrongdoing. 
The Federal Communications Commission 
caught wind of Comcast's business practice, 
which ignited an investigation. In August 
2008, the FCC determined that Comcast had 
violated policy. Customers that used peer-to- 
peer software programs, such as BitTorrent, 
Ares, eDonkey, FastTrack, and Gnutella, are 
eligible to collect from the settlement. 



Cut Down On 
Help Desk Calls 

Reduce Wasted Time On The Phone 
While Offering Better Service 



by Bruce Gain 

The help desk is usually the most direct 
link users have with the IT department. 
As a provider of services, it is also where 
IT can often either shine or fail in the 
eyes of the users. One way to develop 
your service model is by improving 
processes, so calls to the help desk do not 
have to be made in the first place. Here 
are some tips on how to cut the number 
of help desk calls while offering better 
all-around service. 

Improve The Service Model 

IT departments are increasingly adopt- 
ing a service model in the enterprise, 
which, among other things, is seen as an 
integral component of how enterprises 
realize their goals. By providing a better 
service, the amount of help desk calls 
can decrease. 

"Being more efficient at how you pro- 
vide support is a way to cut down on job 
tickets. If you manage your services bet- 
ter, you better understand what you are 
doing," says Paul Ille, director of technical 
services for Alloy Software (www. alloy- 
software. com). "IT departments I have 
worked with in the past sometimes don't 
understand exactly what it is that they are 
providing. Better understanding the ser- 
vices you provide and understanding how 
you measure those services definitely 
makes you more efficient. 

"The best help desk ticket is the one that 
never happens," says John Baschab, man- 
aging director of the Provali Group 
(www.provaligroup.com). "Keeping tick- 
ets from ever happening means having 
well-managed, standardized systems." 

Help Users Help Themselves 

Many help desk calls can be avoided by 
offering users access to information to 
resolve issues on their own, especially 
when solving more common problems, 
such as password changes. The informa- 
tion can be made available online with 
access limited to the enterprise's users. 

Private enterprise social networking 
applications or forums can complement 
self-help internal databases, Ille says. 
Baschab agrees: "Having everything tied 
into an in-depth knowledgebase packed 



BONUS TIPS 



■ Keep spares on hand. Having spare equip- 
ment available in the event of a system failure 
can enable users to switch machines with a 
backup while mitigating repeat calls to the help 
desk. The user can then send an email instead 
of calling the help desk in a panic. "I like to have 
spare equipment ready, so if it breaks, they can 
go and get the spare," says John Matzek, CEO 
of Logic IT Consulting (www.logicitc.com). 

■ Give users adequate training. Sometimes 
users are seeking advice from the help desk. 



with information that can help customers 
solve their issues prior to contacting you 
always helps." 

However, you do not want to encourage 
too much self-service, either. Although 
users can find quick and efficient fixes 
themselves in an internal database that the 
in-house IT department has created, it is 
not a good idea for users to begin resolv- 
ing all problems by themselves. IT 
admins, for example, will regularly access 
public forums, social networking sites, 
trade press articles (such as those that 
Processor publishes), and other outlets to 
find information for certain fixes. 
However, users who seek information for 
fixes beyond what the IT department com- 
municates can pose risks. 

"How qualified are the people who are 
finding fixes on Google and applying 
them? In an internal knowledgebase, you 
have approved the fix and know it works," 
Ille says. "If users find something on 
Google that they think is a good fix, it 
might wind up causing some unintended 
consequences. What if they download a 
patch that causes excess network traffic or 
is not even a real fix but a virus?" 

Track & Communicate 
Common Problems 

Software programs that track job tick- 
ets and user support can be especially 
beneficial when trying to reduce the num- 
ber of help desk calls. Software, for 
example, can rank the most common 
types of problems. It is then possible to 
either take action to prevent repeat occur- 
rences of the problems or to add fixes to 
common problems to the self-help data- 
base that users can access to solve the 
issues on their own. 

Analyzing common problems and issu- 
ing reports for users to access does not 
require many resources or much time, but 
the payoff can be big. "Translating the 
help desk team's internal notes and knowl- 
edge base into a shared system that users 
can access and search often requires only a 
small amount of incremental effort," 
Baschab says. 

Even non-tech communications can 
work. John Matzek, co-CEO of Logic IT 
Consulting (www.logicitc.com), for exam- 
ple, says many users at one firm were 



not for technical problems they are having, but 
because of a lack of knowledge about a par- 
ticular application. This is where user training 
is required. 

"If people do not know how to use Microsoft 
Outlook, then they are going to submit a lot of 
job tickets," says Paul Ille, director of technical 
services for Alloy Software (www. alloy-soft 
ware.com). 'This scenario is for trainers, who 
then devote time to helping people with those 
applications to cut down on support." 



Best Tip: 

Prioritize Help Desk Calls 

Smart help desk management involves prior- 
itizing the severity of problems and determin- 
ing when the best time is to fix the problems. 
A poorly managed help desk that is inundat- 
ed with calls during peak calling hours might 
fix problems on a first-call, first-serve basis. 
However, this reactive approach runs the 
risk of call logjams, which can add exponen- 
tially to the number of callbacks and time 
spent on job tickets. 

Instead, John Baschab, managing director of 
the Provali Group (www.provaligroup.com), 
recommends categorizing help desk calls in 
terms of difficult-to-solve vs. time-to-solve job 
tickets. "One way to increase help desk pro- 
ductivity is to deal with easy-to-solve but time- 
consuming tickets during non-peak hours," 
Baschab says. "Implementing this requires a 
little deeper analysis of tickets and some extra 
effort to ensure that the processes properly 
handle [more critical] issues. However, the 
payoff can be large in terms of cost, response 
time, and end-user satisfaction." 

Most Practical Tip: 

Designate User Points 
Of Contact 

Designating people in different departments 
who are more familiar with IT problems and 
processes can serve as a conduit between 
the help desk and other users, says John 
Matzek, co-CEO of Logic IT Consulting (www 
.logicitc.com). 

The point-of-contact person can call IT help 
desks on behalf of other users and reduce 
call volumes by filtering out unnecessary job 
tickets while more efficiently working with IT 
to reduce issues that require IT's input. 

"These people are more familiar with the 
process, and we will know each other's work- 
ing style because we have worked together 
consistently," Matzek says. 



having difficulties with printing from a 
terminal server. Instead of going the 
online route, Matzek made sure that the 
fixes were posted where people would see 
them. "I made a document explaining how 
to log in and how to print, and I pasted it 
on every workstation," Matzek says. 
"Then, we never got that call again about 
[problems with the printing] because it 
was in the document." 

Contact Users Before They Call 

Good monitoring software that sends 
alerts when things go wrong can enable 
admins to communicate problems to users 
before they have time to inundate the help 
desk with calls. If the enterprise's Internet 
provider has an outage, a server goes 
down, or there is another major problem, 
an all-point email alert communicating 
that the IT department is aware of the 
problem can quickly ward off legions of 
distraught and panicked users calling to 
find out what is wrong. In addition to 
email, the same message can be commu- 
nicated in an automated recording that 
users hear when they first try calling the 
help desk. 

"You need to be able to let them know 
that you are working [on the problem]," 
Matzek says. "That way they are not all 
calling you all at once." 
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INFO-TECH • INSIGHT 



Storage Vendors: 
Heroes Or Villains 
Of The Cloud? 



I In the most recent Batman movie, a 
I good guy character destined to turn bad 
foreshadows his own fate by saying, "You 
either die a hero or you live long enough to 
see yourself become the villain." As we enter 
the age of internal/external clouds, I wonder 
if traditional networked storage may be in 
danger of going from hero to villain. 

Storage-area network, or SAN, arrays 
might not be heroic, but they have been a 
utility infrastructure champion of sorts. A 
SAN array is a foundation of converged 
infrastructures that also leverages server vir- 
tualization. We used to call these converged 
and abstracted "utility infrastructures." Now 
they're being called "internal clouds." 

The main difference between internal and 
external clouds is simply who owns the hard- 
ware underneath it all. In the future, expect 
more buzz about both internal and external 
clouds as well as how the two might be fed- 
erated with application workloads moving 
from one to the other. This could have pro- 
found implications for storage management. 

SAN Array As The "Good Guy" 

For many of us, the journey through ser- 
ver virtualization, to infrastructure virualiza- 
tion, to so-called internal clouds began with 
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Storage. When I was researching storage-area 
networks for midsized enterprises five years 
ago, I asked implementers what the main 
business drivers were for investing in a SAN. 

The main response was typically "We 
have too many servers." Close behind was a 
desire to extend enhanced business continu- 
ity and disaster recovery to the growing num- 
ber of x86/x64 servers. Infrastructure consol- 
idation and risk management were bigger 
drivers than capacity and performance issues. 

Server virtualization was the other impor- 
tant development for consolidation and risk 



management. First you separate processing 
from storage by putting the storage in a SAN 
array. Then you can consolidate the process- 
ing — getting more utilization out of fewer 
processors — by employing virtualization. 

SAN Array As The Potential Villain 

Another finding of that earlier research on 
SANs was that, unlike the x86/x64 servers 
that were increasingly being attached 
to them, SAN arrays remained highly 
proprietary. What differentiated one 
array from another was not so much the 
spinning disks and network connection that 
made up the SAN but more the software 
inside the arrays for managing features such 
as replication and storage volume. 

This is not unusual behavior. Traditionally, 
one of the best ways to make money in the 
tech business has been to take a function that 
can be programmed on a server, wrap it in its 
own separate hardware, and sell it as a dis- 
crete appliance. It's been done with other 
functions such as security firewalls and virtu- 
al private network gateways. 

In SAN and network-attached storage 
arrays, it is the storage management function 
of a server that is productized (and mone- 
tized) as a separate appliance. 

But in the abstracted world of the cloud, 
things are going the other direction. A soft- 
ware function is now wrapped in a virtual 
appliance that runs on standardized process- 
ing infrastructure. This is where SAN hard- 
ware-embedded storage management could 
become more of a hindrance than a helper. 

Functions, Not Hardware, Live In A Cloud 

Take, for example, the case of the mid- 
sized company exploring the possibilities of 



third-party clouds in disaster recovery. This 
company has successfully consolidated its 
infrastructure with blade servers, virtual 
machines, and SAN storage. It has also start- 
ed to use site-to-site replication between two 
locations for disaster recovery. 

Here is the question: If the second location 
is essentially providing standby capacity for 
DR purposes, wouldn't it be even cheaper to 
replicate to a third-party cloud compute 
provider? In a metered cloud, you only pay 
for the virtual servers when they are active. 
So maintaining standby capacity there should 
cost very little. 

Here is the problem: The replication they 
use now is vendor-proprietary. You need a 
physical box from the storage vendor at each 
location and to set up replication between the 
two. You can't locate a proprietary box in a 
cloud, so the external cloud service can't be a 
replication target. 

Sticking Around Too Long? 

Ultimately, the solution to this dilemma 
will be for features such as repUcation to be 
managed outside of the physical array that 
holds the disks. There are developments that 
point in this direction. These include host- 
based replication (moving replication to the 
virtual servers), virtualization of storage con- 
trollers, and moving more storage manage- 
ment into the virtual infrastructure. 

All this is promising, but right now, 
advanced storage management in a SAN 
remains largely array-based. As infrastruc- 
ture management becomes more abstracted 
in both internal and external clouds, these 
proprietary approaches may find that they 
have stuck around long enough to become 
the villain. 
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Processor 
Solutions Directory 

Here are brief snapshots of several companies 
offering products designed for the data center and 
IT industry. Listings are sorted by category, 
making it easy for you to find and compare companies 
offering the products and services you need. 

You can find more detailed information on these 
companies and the products they offer inside this issue. 



To list your company and products, 
call (800) 247-4880. 



Physical Infrastructure 



BayTech was founded in 1976 and, since the 1990s, has 
developed unique products for remote power management. 
The company uses printed circuit board instead of wires for a 
better, more resilient connection between the data center 
equipment and the receptacle. BayTech provides an exten- 
sive Web site with brochure downloads, warranty informa- 
tion, and reseller support and also offers evaluation units for 
data centers. 

Products Sold: 

• Power control, distribution, management, and metering 

• Power transfer switches 

• Console management and remote site management 



(800) 523-2702 I www.baytech.net 



Physical Infrastructure 



PDUs 



direct 



Established in 2008, PDUsDirect.com is an online whole- 
saler providing a select line of PDUs for sen/er and net- 
worked environments. PDUs Direct's basic, metered, and 
switched Rack PDUs provide local and remote power 
management, power monitoring, and environmental moni- 
toring. We pride ourselves in offering industrial-grade qual- 
ity products at the lowest prices, with the fastest shipping 
(most orders shipped within 24 hours) and simplest pur- 
chase process. 

Products Sold: 

A complete line of 20A PDUs, including metered, basic, 
and switched. 



751-7387 I pdusdirect.com 



Storage 




O DUCTS 



Established in 1983, CMS Products is a leading innovator 
in data backup, encryption, and security technology. CMS 
Products has received global recognition for its work in 
developing leading-edge, easy-to-use products that 
revolutionize the notebook and desktop data backup/ 
restore and storage industry. 

Products Sold: 

• Backup and restore disaster recovery software and sys- 
tems, including laptop, desktop, and secure versions 

• Laptop hard drive upgrades 

• Data security products, including encryption software, 
encrypted portable backup, and encrypted flash drives 



(800)327-5773 | www.cmsproducts.com 



Physical Infrastructure 



AUSTIN 

Founded in 1 995, Austin Hughes Electronics is a design and 
manufacturing company offering a broad range of electro- 
mechanical products based on 19-inch rackmount technolo- 
gy. Austin Hughes has ISO 14001 & 9001 -approved design, 
manufacturing, assembly, and test facilities in Hong Kong 
and China. It has sales offices throughout the Asia-Pacific 
region as well as Europe and the United States, supporting 
a worldwide distributor network. 

Products Sold: 

• Rackmount LCD keyboard/KVM drawers 

• Rackmount serial console LCD keyboard drawers 

• LCD screens 



www.austln-hughes.com 



Physical Infrastructure 



CYBER@SWITCHING 



® 



Cyber Switching began pioneering power distribution 
technologies in 1994. Our PDUs are used to power cycle 
and manage power to blade servers, routers, SANs, and 
other data center equipment. Our intelligent PDUs can 
monitor current individually by outlet and also provide virtual 
circuit breaker protection on an individual outlet basis. No 
other PDU on the market offers these unique features. 



Products Sold: 

• Intelligent power management 

• Value-added power management 

• Metered power distribution 

• Three-phase power distribution 



Energy management 
and control 
Switches 
Patch Panels 



311-6277 I www.cyberswitching.com 



Physical Infrastructure 



RACKMOUNT 

SaLUTiaNS,Ltd 

risr service matters. 




Rackmount Solutions' mission is to listen to the IT engi- 
neer's specific needs and deliver superb-quality, high-per- 
formance products through continuous product innovation 
and operational excellence. We pride ourselves in provid- 
ing quality customer sen/ice, products that fit your IT 
requirements, and solid value for your money. 

Products Sold: 

• Wallmount and sen/er racks and cabinets, including 
sound proof, air conditioned, and large cable bundle 

• Desktop/tabletop portable racks 

• Shockmount shipping cases 

• Bulk cable 



(866)207-6631 I www.rackmountsolutlons.net 



Servers 



IINJ lAJItVJ 



IN-WIN Development Inc., an ISO 9001 manufacturer of 
professional computer chassis, power supplies, and digi- 
tal storage devices, is the leading provider of enclosure 
solutions to system integrators worldwide. Founded in 
1986, IN-WIN provides high-quality chassis that conform 
to all safety regulations, as well as unsurpassed cus- 
tomer service. 

Products Sold: 

• Computer cases 

• Sen/er cases 

• Power supplies 

• Storage devices 



Physical Infrastructure 



S^AVTECH 



AVTECH Software, founded in 1988, is focused on making 
the monitoring and management of systems, servers, net- 
works, and data center environments easier. AVTECH pro- 
vides powerful, easy-to-use software and hardware that 
saves organizations time and money while improving opera- 
tional efficiency and preparedness. AVTECH products use 
advanced alerting technologies to communicate critical status 
information and can perform automatic corrective actions. 

Products Sold: 

A full range of products that monitor the IT and facilities 
environment, including temperature, humidity, power, 
flood, room entry, and UPS 



220-6700 I www.AVTECH.com 



Physical Infrastructure 




Based in New York City, Hergo Ergonomic Support 
Systems is an independent designer and manufacturer of 
enclosure cabinet solutions, technical computer furniture, 
and modular racking systems. The company's products 
are designed to promote organization in the workspace 
and to increase the productivity of computers, peripherals, 
and communications equipment. Hergo is known for its 
high-quality products and superior customer service. 



Products Sold: 

• Racks 

• Enclosures/cabinets 

• Motorized workstations 

• Flat-panel arms 



Computer desks 
Cable management 
Power management 



222-7270 I www.hergo.com 




Physical Infrastructure 



Server Technolosy 

Solutions for ttie Data Center Equipment Cabinet 



Server Technology is committed to the PDU market with the 
largest group of engineers dedicated to power distribution 
and other solutions within the equipment cabinet. Advance- 
ments in device power monitoring help data centers monitor 
and improve their efficiency, and continuous research and 
development is fueled by companies that look to Server 
Technology for their custom cabinet power solutions. 

Products Sold: 

A complete line of cabinet PDUs, including Per Outlet 
Power Sensing (POPS), Rack Mount Fail-Safe Transfer 
Switch, Console Port access with remote power manage- 
ment. Switched, Smart, Metered, Basic, and -48 VDC 



(800)835-1515 I www.servertech.com 



Clients 



(909)348-0588 | www.ln-wln.us 



Patacap 



Currently headquartered in Tarrytown, N.Y., Datacap was 
founded in 1988. Specializing in software solutions for 
document capture and forms processing, Datacap markets 
its products not only to resellers and system integrators, 
but also directly to end users. Datacap has received 
numerous awards for its innovative technology and is 
responsible for several firsts in the industry, such as the 
first forms processing solution for the PC in 1989 and the 
first Web-based capture solution in 2000. 

Products Sold: 

Data and document capture programs 



(914) 366-0100 I www.datacap.com 
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Clients 



^^dtSearch' 

www.dtsearch.com 



Maryland-based dtSearch started research and develop- 
ment in text retrieval in 1988. The company is known for 
speedy adoption of new programming standards, OSes, 
and file types. Plus, it has a flexible licensing model. 
Typical corporate use of dtSearch includes general Infor- 
mation retrieval, Internet and intranet site searching, and 
email archiving and email filtering. 

Products Sold: 

Text retrieval products, including: 

• Desktop With Spider • Web With Spider 

• Network With Spider • Engine For Win & .NET 

• Publish For CD/DVDs • Engine For Linux 



(800)483-4637 I www.dtsearch.com 



Equipment Dealer 



IrfiVJhitJtler 



• PaceButler buys used cell phones. 

• In business since 1987 

• Redeploy your used phones after upgrade 

• Donation option - directly to the non-profit of your choice 

• Dedicated to customer satisfaction 

- A+ Rating with the Better Business Bureau 

- Payment issued in four days 

• Dedicated to employee development 

- Book reading program 

- Health and fitness programs 

Products Sold: 

We buy used cell phones & PDAs, including Apple, LG, 
Blackberry, HTC, Motorola, Nextel, Nokia, PalmOne & 
Samsung. 



(800)248-5360 I www.pacebutler.com 



Equipment Dealer 




IGS is an independent manufacturer and source of supply, 
service, and depot repair of obsolete Digital Equipment 
Corp. parts, products, and systems. We maintain an exten- 
sive inventory of DEC parts and equipment; some date from 
the 1960s. We refurbish and service these parts, adding 
current technology when applicable. We provide Advance 
Replacement Service within 24 hours if we have the item in 
stock and, with 75,000 stock items, chances are we will. 

Products Sold: 

Digital Equipment Corp. parts, products, and systems, 
including memory, storage, processors, display and video, 
printers, and cables, for repair, lease, or rental 



332-7278 I www.decparts.com 



Equipment Dealer 




In 1987, Pegasus Computer Marketing started providing 
mainframe products to the end-user market. What began as 
a sales-only organization soon adapted to offer in-house 
repair and refurbishment. During the past 10 years, Pegasus 
has focused primarily on the point-of-sale and barcode 
industries, buying, selling, and providing service contracts for 
anywhere from a few scanners to hundreds. 

Products Sold: 

We buy, sell, and service: 

• Point-Of-Sale Equipment and POS/PC Flat Panels 

• Wired and Wireless Barcode Hardware 

• Kronos Time Clocks and Accessories 



(800) 856-2111 I www.pegasuscomputer.net 



Equipment Dealer 



Information 
Technology 
Trading 



At Information Technology Trading, our goal is to help you 
acquire the right hardware or software solution. We special- 
ize in purchasing and reselling data-processing equipment 
and have more than 21 years combined experience. We pro- 
vide services and system upgrades, DASD, communication, 
and memory. We're also an outlet for off-lease portfolios. 

Products Sold: 

• AS400, Advanced System/36, R/S6000, ES/9000, and 
PC systems (including lease and rental) 

• CPUs, memory, disks, tapes, displays, and controllers 

• Services, including system design and installation, 
maintenance, and buyback of existing hardware 



(877)715-3686 I www.itechtrading.com 
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Their computer. 
Your brain. 

GoToAssist® Express'" lets you view and control 
your customer's computer online, so you can use 
your expertise to instantly fix the problem. You'll 
solve technical issues faster while reducing travel 
costs and increasing customer satisfaction. 
Support Smarter™ with GoToAssist Express. 



FREE 30-Day Trial 

gotoassist.com/processor 
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